Repository navigation
Implement all SPDX 3 getters - #290
Conversation
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
It will return None and let user handle that. Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
|
@bact: Whoa. This is great! And thank you for the nicely done report too. Here's my philosophy. I say that we merge this, cut a new release, and then let you and others to find the bugs. I did a review, checked your new tests, and I didn't see anything that worried me. But I think getting more eyes and users is the best way to find bugs, so please merge this, if you agree :) Great job! |
|
Thank you both. I will merge this now. I will update changelog and few docs, including CONTRIBUTING.md, to reflect current dev environment. |
@jspeed-meyers @goneall Thanks again for the reviews and stuff. I have released this as v4.0.0 at https://github.com/spdx/ntia-conformance-checker/releases/tag/v4.0.0 - and waiting for bug reports and feedbacks. |
(Replacing PR #286. With this PR, SPDX 3 support should be completed for the existing checkers (NTIA and FSCTv3))
Add check methods for both SPDX 2 and SPDX 3:
Implement SDPX 3 support for:
With a number of basic pytests.
Notes:
get_components_without_*methods will searching for/Software/Package/(and subclasses) that does not have the properties.get_components_without_identifiers()where it works at/Core/Elementlevel./Software/Package/level means they will not cover/Software/File,/Software/Snippetand other/Software/SoftwareArtifact. This is to follow the existing implementation for SPDX 2 which iterate overself.doc.packages.iter_objects_with_property().get_components_without_identifiers()may never be used. If we need an ability to check this, we need a parser/deserializer that can work with invalid/incomplete SBOM.