Does this BOM account for what it read?
Drop in a CycloneDX BOM. The check reads the coverage statement the scanner carries and rules on it against the Coverage Attestation Profile, rule by rule. Nothing leaves this page.
CycloneDX JSON
What this check reads
It reads the statement a scanner makes about its own run. A count carried by file extension is a remainder, and rule R1 refuses a remainder because no one can check which files it holds. Reading a tree to name every file needs the files, which stay on your machine: run cbom-check.mjs <bom.json> --tree <dir> beside the repository.
A BOM that states no coverage in a shape this check recognises is reported as exactly that. The recognised shapes are listed in the result.