Skip to content

Implement all SPDX 3 getters - #290

Merged
bact merged 7 commits into
spdx:mainfrom
bact:separate-spdx3-utils
Sep 5, 2025
Merged

bact merged 7 commits into
spdx:mainfrom
bact:separate-spdx3-utils

Conversation

@bact

@bact bact commented Sep 4, 2025 •

Copy link
Copy Markdown
Collaborator

(Replacing PR #286. With this PR, SPDX 3 support should be completed for the existing checkers (NTIA and FSCTv3))

Add check methods for both SPDX 2 and SPDX 3:

  • check_author()
  • check_timestamp()

Implement SDPX 3 support for:

  • get_components_without_names()
  • get_components_without_identifiers()
  • get_components_without_versions()
  • get_components_without_concluded_licenses()
  • get_components_without_copyright_texts()

With a number of basic pytests.

Notes:

  • See this GSoC 2025 report for design details
  • The SPDX 3 get_components_without_* methods will searching for /Software/Package/ (and subclasses) that does not have the properties.
    • ** The exception is get_components_without_identifiers() where it works at /Core/Element level.
    • Working at /Software/Package/ level means they will not cover /Software/File, /Software/Snippet and other /Software/SoftwareArtifact. This is to follow the existing implementation for SPDX 2 which iterate over self.doc.packages.
    • We can change which set of objects we like to iterate over. See code lines that we call iter_objects_with_property().
    • The NTIA document uses the term "component" and may be it's up to the interpretation what "component" (and "subcomponent") should cover. Future version of checker may allow user to choose the subcomponent level to scan.
  • Also note that as SPDX 3 requires all elements to have spdxId, the JSON deserializer will raise a ValueError if there is a missing spdxId - so in practice, get_components_without_identifiers() may never be used. If we need an ability to check this, we need a parser/deserializer that can work with invalid/incomplete SBOM.
  • The code is updated and fixed to work with type checks based on type hints from the new spdx-python-model 0.0.3

bact added 3 commits September 3, 2025 14:18
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
@bact bact added the enhancement New feature or request label Sep 4, 2025
bact added 3 commits September 4, 2025 18:35
It will return None and let user handle that.

Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
@jspeed-meyers

Copy link
Copy Markdown
Collaborator

@bact: Whoa. This is great!

And thank you for the nicely done report too.

Here's my philosophy. I say that we merge this, cut a new release, and then let you and others to find the bugs. I did a review, checked your new tests, and I didn't see anything that worried me. But I think getting more eyes and users is the best way to find bugs, so please merge this, if you agree :)

Great job!

@goneall goneall left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This all looks good to me

Thanks @bact

@bact

bact commented Sep 5, 2025

Copy link
Copy Markdown
Collaborator Author

Thank you both. I will merge this now.

I will update changelog and few docs, including CONTRIBUTING.md, to reflect current dev environment.

@bact
bact merged commit ace2ea8 into spdx:main Sep 5, 2025
24 checks passed
@bact
bact deleted the separate-spdx3-utils branch September 5, 2025 06:51
@bact

bact commented Sep 5, 2025

Copy link
Copy Markdown
Collaborator Author

@bact: Whoa. This is great!

And thank you for the nicely done report too.

Here's my philosophy. I say that we merge this, cut a new release, and then let you and others to find the bugs. I did a review, checked your new tests, and I didn't see anything that worried me. But I think getting more eyes and users is the best way to find bugs, so please merge this, if you agree :)

Great job!

@jspeed-meyers @goneall Thanks again for the reviews and stuff. I have released this as v4.0.0 at https://github.com/spdx/ntia-conformance-checker/releases/tag/v4.0.0 - and waiting for bug reports and feedbacks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants