CycloneDX / CycloneDX/cyclonedx-dotnet-library

Plans to split out the SPDX libraries from this repo

Open
#436 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
C#
Stars
28
Forks
35
PR merge metrics
No merged PRs in 30d

Description

The SPDX libraries were originally added to this repo to make it easier to initially iterate on the implementation in step with the CDX libraries in this repo.

I'm proposing to migrate the SPDX and SPDX Interop libraries to their own individual repos.

There's a couple of potential benefits including:

- reduced notification fatigue for maintainers who are focused on the CDX libraries and not the SPDX ones
- finer grained scope for potential future maintainers to be onboarded
- the opportunity to more easily open up SPDX libraries to external collaborators from the SPDX community

I can't think of any real downsides except library versions will start drifting between the core CDX libraries and the SPDX ones.

Contributor guide

Open the contributing guide

Research direction

Review how the SPDX and SPDX Interop libraries are organized within this repository and how they relate to the CDX libraries. Define the repository boundaries and migration plan before making changes; done means both SPDX libraries have been migrated to individual repositories without losing their intended collaboration and maintenance scope.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
tooling
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.