anchore / anchore/syft

Adapt new and existing package metadata as SPDX relationships

Open
#476 7 comments 0 reactions 0 assignees View on GitHub
blocked enhancement format:spdx
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
23h 27m
Merged PRs (30d)
48

Description

SPDX has the concept of relationships that can be applied to packages, files, or other artifacts. This issue aims to explore what existing metadata can be expressed via SPDX relationships as well as potentially add more metadata to collect via the catalogers that can be expressed as SPDX relationships.

Internal to syft there is already the concept of package-to-package relationships, what isn't clear is if this should be further expanded generally or isolated only to the SPDX presenter (which is generally a new concept, since all data typically gets expressed via the JSON model first).

Contributor guide

Open the contributing guide

Research direction

Start by reviewing Syft's existing package-to-package relationship concept and the SPDX presenter to determine which metadata is already represented. Done means documenting or implementing a decided scope for SPDX relationships and resolving whether the behavior belongs in the shared JSON model or only in the SPDX presenter.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.