aboutcode-org / aboutcode-org/scancode-toolkit

Support for SPDX 3.0

未關閉
#3,867 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
new feature
主要語言
Python
星號
2.6k
分支
791
平均合併
1 天 12 小時
30 天內合併 PR
5

描述

## Short Description

Scancode Toolkit should support SPDX v3 exports as well.

## Possible Labels

- new feature
- sbom

## Select Category

- [x] Enhancement
- [ ] Add License/Copyright
- [ ] Scan Feature
- [ ] Packaging
- [ ] Documentation
- [ ] Expand Support
- [x] Other

## **Describe the Update**

At the moment, Scancode Toolkit uses SPDX 2.2.1, which corresponds to ISO/IEC 5962:2021. Two months ago, version 3.0 has been released with a large overhaul. Scancode Toolkit should support the new specification and its documented output formats: https://spdx.github.io/spdx-spec/v3.0/serializations/#42-rdf-serialization

## **How This Feature will help you/your organization**

Keep Scancode Toolkit in sync with the latest standards.

## **Possible Solution/Implementation Details**

We might need a switch to decide between version 2.2 and 3.0 to support multiple use-cases, for example interoperability with recent tooling, while still allowing for ISO conformance if required.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。