spdx / spdx/tools-java

Validate Custom JSON-LD Context

Aperta
#263 2 commenti 1 reazione 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

enhancement
Lingua principale
Java
Stelle
101
Fork
46
Merge medio
9h 43m
PR unite (30g)
8

Descrizione

According to the Serialization Information section in the SPDX 3.0.1 spec serializing NamespaceMaps within the @context field for JSON-LD serializations is valid.

When serializing a physical SpdxDocument, any property of the logical element that can be natively represented within the chosen serialization format (e.g., @context prefixes in JSON-LD instead of the namespaceMap) may utilize these native mechanisms. All remaining properties shall be serialized within the SpdxDocument element itself.
[...]
Additional namespace mappings may be defined within a separate object within the context.

The java spdx tools however do not currently support this.
Take for example the following document: sbom-output.spdx.json

export SPDX_TOOLS_VERSION=2.0.2
curl -sLO "https://github.com/spdx/tools-java/releases/download/v${SPDX_TOOLS_VERSION}/tools-java-${SPDX_TOOLS_VERSION}.zip"
unzip -j "tools-java-${SPDX_TOOLS_VERSION}.zip" "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar"
java -jar "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar" Verify "sbom-output.spdx.json"

The java tools fail with

This SPDX Document is not valid due to:
        $.@context: must be the constant value 'https://spdx.org/rdf/3.0.1/spdx-context.jsonld'

even though the document should be valid.

An easy way to fix this would be to expand the custom context before processing the SPDX document.
See for example expand-custom-context.sh

./expand-custom-context.sh sbom-output.spdx.json

This small script expands the custom context and outputs expanded-sbom-output.spdx.json which successfully gets validated by the java tools.

java -jar "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar" Verify "expanded-sbom-output.spdx.json"
This SPDX Document is valid.

It would be helpful if this behavior could be supported directly by the java-tools.

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Esegui il comando Verify dell’issue su sbom-output.spdx.json, quindi confrontalo con expanded-sbom-output.spdx.json prodotto da expand-custom-context.sh. Parti dalla convalida del contesto JSON-LD del comando Verify e determina come devono essere gestite le mappature di contesto personalizzate; il lavoro è completato quando il documento originale viene convalidato senza richiedere lo script esterno di espansione.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
java
Ambito
cli, tooling
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
45/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.