Evidence in location

Hello!
when I scan and get an SBOM, do I expect at least one of the locations of a given package will have an evidence of “primary”?

Thanks!

@TimBrown1611 I believe so, but I’m not aware of any testing that enforces this fact. What inference are you trying to make from this?

You can see catalogers making packages marked with primary evidence locations, for example, here:

Why do you ask? I feel like I could give a better answer with more context.

I am working on this PR - Squashed all layers by tomersein · Pull Request #3138 · anchore/syft · GitHub
I’m trying to build a cleaner to packages which doesn’t exist in the squash mode by looking at annotations
like here - Squashed all layers by tomersein · Pull Request #3138 · anchore/syft · GitHub