CycloneDX / CycloneDX/cyclonedx-python-lib
feat!: (re)move non-standard implementations
- Ngôn ngữ chính
- Python
- Star
- 116
- Fork
- 67
- Merge trung bình
- 8 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 2
Mô tả
This library claims to implement the CycloneDX standard. And it doe.
but it also has some implementation parts that are not standard - they should be moved to the "contrib" area, or removed entirely.
## Goal
- [ ] move helpers/factories/builders to the "contrib" area
- #916
- remove the (old) deprecated exports
- remove the usage of external models
- [ ] `Compoennt.purl` is no longer an instance of `PackageUrl` but a simple `str` or instance of string-castable
- cast to string on normalization
- downstream users can still use a PackageURL object, if needed ....
- remove `packageurl` dependency
- #939
- [ ] validation of external standards -like SPDX expressios and such...
- [ ] don't use UUID for `bom.serailNumber` - this is a string ...
- tbc...
## Motivation:
- have a clean standard implementation, no opinionated fluff, only models and (de)serailization.
Hướng dẫn đóng góp
Hướng nghiên cứu
The issue covers helpers, factories, builders, deprecated exports, Component.purl, the packageurl dependency, SPDX-like validation, and bom.serialNumber. Start by inventorying those areas and reviewing linked issues #916 and #939. Done means the non-standard implementations are moved or removed and the remaining models and serialization stay aligned with the stated standard.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- python
- Lĩnh vực
- backend-api-design
- Loại issue
- Tái cấu trúc
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 20/100