CycloneDX / CycloneDX/cyclonedx-python-lib

[TRACKING] Complete support for CycloneDX v1.5

未关闭
#578 1 条评论 5 个 reaction 已指派 0 人 在 GitHub 查看
enhancement help wanted schema 1.5
主要语言
Python
星标
116
派生
67
平均合并
8 天 2 小时
30 天内合并 PR
2

描述

see https://github.com/CycloneDX/specification/releases/tag/1.5

The following items are not currently supported for CycloneDX v1.5 (as of release 6.4.x):

- [x] Missing `lifecycles` on `bom.metadata`
see #698
- [ ] Missing `modelCard` on `Component`
- #912
- [ ] Missing `data` on `Component`
- #913
- [x] Missing `bom-ref` attribute on `OrganizationalContact`
- possible fix: #859
- [x] Missing `bom-ref` attribute on `OrganizationalEntity`
- see #799
- possible fix: #859
- [x] Missing `bom-ref` attribute on `LicenseExpression`
- possible fix: #859
- [ ] Missing `licensing` on `DisjunctiveLicense`
- see #948
- [x] Missing `properties` on `DisjunctiveLicense`
- see #947
- [x] Missing `bom-ref` attribute on `DisjunctiveLicense`
- possible fix: #859
- [x] Missing `identity` on `ComponentEvidence`
- see #810
- see #900
- [x] Missing `occurrences` on `ComponentEvidence`
- see #810
- [x] Missing `callstack` on `ComponentEvidence`
- see #810
- [ ] Missing `trust_zone` in `Service`
- see https://github.com/CycloneDX/cyclonedx-python-lib/pull/980
- [ ] Missing `annotations` on `Bom`
- [ ] Missing `formulation` on `Bom`
- [x] `Bom.metadata.tools` missing support for `components` and `services` along with deprecation of `Tool`
- see #561
- see https://github.com/CycloneDX/cyclonedx-python-lib/issues/597
- to be continued

-----

this library is a community effort.
if you find a feature that you need is missing, feel free to donate/contribute the missing feature.
- see #633

贡献指南

打开贡献指南

调研方向

审查 CycloneDX v1.5 发布版本和未解决的检查清单条目,尤其是链接的 issue #912、#913 和 #948,以及为 Service trust zones 引用的 pull request。这是一个跟踪 issue,而不是专注于代码的任务;当剩余的 v1.5 项目都已实现,并且其检查清单条目可以标记为完成时,即表示完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
需要澄清
新手友好度
20/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。