CycloneDX / CycloneDX/cyclonedx-php-composer

feat: set dev-dependencies `component.scope` to `excluded`

Open
#461 0 comments 0 reactions 0 assignees View on GitHub
enhancement good first issue hacktoberfest help wanted
Dominant language
PHP
Stars
87
Forks
7
PR merge metrics
No merged PRs in 30d

Description

## Is your feature request related to a problem? Please describe.

Per CycloneDX specification, the components' scope means (see [docs](https://cyclonedx.org/docs/1.6/json/#components_items_scope))

- "required": The component is required for runtime
- "optional": The component is optional at runtime. Optional components are components that are not capable of being called due to them not be installed or otherwise accessible by any means. Components that are installed but due to configuration or other restrictions are prohibited from being called must be scoped as 'required'.
- "excluded": Components that are excluded provide the ability to document component usage for test and other non-runtime purposes. Excluded components are not reachable within a call graph at runtime.

Current implementation does not set any scope, meaning the fallback to "required".
for dev-dependencies this would be wrong.

## Describe the solution you'd like

mark all components, that are dev-dependencies only,
- as "scope=excluded" in the resulting SBOM.
- add a property "cdx:composer:package:isDevRequirement=true" as of https://cyclonedx.github.io/cyclonedx-property-taxonomy/cdx/composer.html

## Describe alternatives you've considered

none

## Additional context

Add any other context or screenshots about the feature request here.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.