-
Notifications
You must be signed in to change notification settings - Fork 597
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Invalid SPDX: missing copyright text #3346
Comments
Hey @vargenau -- would you mind posting the error you are getting? We seem to be having issues running the online validator on this SBOM. Thanks! |
Hello, It's better to download and install locally the Java tools https://github.com/spdx/tools-java or the Python tools https://github.com/spdx/tools-python than using the online tools for big SPDX files. This is the generated SBOM: Running
gives the following result: Most errors are related to #2093 But for this bug report you have:
The Java tools give: |
Thanks @vargenau. I do see the Copyright Text is a mandatory field in SPDX 2.2. We should default this to |
Signed-off-by: Fearkin <[email protected]>
…ailure (#3495) * fixes issue #3346 Signed-off-by: Fearkin <[email protected]> * chore: update schema and unit tests to reflect new copyright property Signed-off-by: Christopher Phillips <[email protected]> * chore: revert schema changes Signed-off-by: Christopher Phillips <[email protected]> * fix: noassert copyright on spdx root package Signed-off-by: Will Murphy <[email protected]> * test: explicitly test spdx 2.2 with tools-java validator Signed-off-by: Will Murphy <[email protected]> * test: update snapshot files Signed-off-by: Will Murphy <[email protected]> --------- Signed-off-by: Fearkin <[email protected]> Signed-off-by: Christopher Phillips <[email protected]> Signed-off-by: Will Murphy <[email protected]> Co-authored-by: Fearkin <[email protected]> Co-authored-by: Will Murphy <[email protected]>
What happened:
Generated SPDX is invalid, mandatory copyright text is missing
What you expected to happen:
SPDX should be valid
Steps to reproduce the issue:
Anything else we need to know?:
Environment:
syft version
:cat /etc/os-release
or similar):macOS 14.7
The text was updated successfully, but these errors were encountered: