CycloneDX / CycloneDX/cyclonedx-python-lib

Improvement: Apply Regex check to `Component.cpe`

未关闭
#580 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement question
主要语言
Python
星标
116
派生
67
平均合并
8 天 2 小时
30 天内合并 PR
2

描述

The CycloneDX scpecification defines a Regex for `Component.cpe`, but this library does not enforce this.

see https://github.com/CycloneDX/specification/blob/c320fc0f0b46873864927d9d5684eea7ba439728/schema/bom-1.5.xsd#L1110-L1112

贡献指南

打开贡献指南

调研方向

Start at the Component.cpe entry point and compare its requirements with the linked CycloneDX schema regex. Done means CPE values are checked against that regex, with focused coverage for valid and invalid values.

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
backend-api-design
Issue 类型
功能
难度
2/5
预计耗时
1-3 小时
活跃度
停滞
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。