Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Adapt new and existing package metadata as SPDX relationships #476

@wagoodman

Description

@wagoodman

SPDX has the concept of relationships that can be applied to packages, files, or other artifacts. This issue aims to explore what existing metadata can be expressed via SPDX relationships as well as potentially add more metadata to collect via the catalogers that can be expressed as SPDX relationships.

Internal to syft there is already the concept of package-to-package relationships, what isn't clear is if this should be further expanded generally or isolated only to the SPDX presenter (which is generally a new concept, since all data typically gets expressed via the JSON model first).

Metadata

Metadata

Assignees

No one assigned

    Labels

    blockedProgress is being stopped by somethingenhancementNew feature or requestformat:spdxSPDX related enhancement or bug

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions