CycloneDX / CycloneDX/cyclonedx-python-lib

Wrong input should result into an exception

Open
#766 2 comments 0 reactions 0 assignees View on GitHub
breaking change
Dominant language
Python
Stars
116
Forks
67
Avg merge
8d 2h
Merged PRs (30d)
2

Description

The code in spdx.py function `is_compound_expression` may run into an exception for several cases, and this results into a `return False`.

This is semantically overloaded.
In case of `False` we cannot distinguish between
- the value cannot be interpreted at all (invalid characters)
- it is a compound expression, but consists of partially unknown, but maybe valid simple (e.g. LicenseRef-*) expression(s)

So it may not be clear what is feasible of how to proceed in case of False.

In case of invalid characters the exception should not be caught, but (re)raised so that an appropriate exception handling can be applied.

The `validate` parameter should be made available in the `is_compound_expression` function to allow either both license item validation along with the compound check or compound check only.

Contributor guide

Open the contributing guide

Research direction

Start in spdx.py at is_compound_expression and trace the exception handling for invalid characters and partially unknown license expressions. Review how the validate parameter is handled elsewhere, then make invalid input propagate an appropriate exception while allowing compound checking with or without license-item validation. Done means callers can distinguish invalid input from a valid compound expression containing unknown items.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
backend
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.