CycloneDX / CycloneDX/cyclonedx-python-lib

feat!: (re)move non-standard implementations

Aperta
#919 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
breaking change contrib refactor
Lingua principale
Python
Stelle
116
Fork
67
Merge medio
8g 2h
PR unite (30g)
2

Descrizione

This library claims to implement the CycloneDX standard. And it doe.

but it also has some implementation parts that are not standard - they should be moved to the "contrib" area, or removed entirely.

## Goal
- [ ] move helpers/factories/builders to the "contrib" area
- #916
- remove the (old) deprecated exports
- remove the usage of external models
- [ ] `Compoennt.purl` is no longer an instance of `PackageUrl` but a simple `str` or instance of string-castable
- cast to string on normalization
- downstream users can still use a PackageURL object, if needed ....
- remove `packageurl` dependency
- #939
- [ ] validation of external standards -like SPDX expressios and such...
- [ ] don't use UUID for `bom.serailNumber` - this is a string ...
- tbc...

## Motivation:
- have a clean standard implementation, no opinionated fluff, only models and (de)serailization.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.