-
-
Notifications
You must be signed in to change notification settings - Fork 84
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade to CycloneDX version 1.6 #489
Comments
requires CycloneDX/cyclonedx-core-java#392 |
@XSpielinbox @hboutemy The CycloneDX Core Java version 9.00 has been released with CycloneDX 1.6 support, thanks to @mr-zepol, @stevespringett, and @nscuro for their help with this. https://github.com/CycloneDX/cyclonedx-core-java/releases/tag/cyclonedx-core-java-9.0.0 |
A heads-up wrt progressing further.
It is being worked on with a fix due ASAP (thanks to @mr-zepol). So, suggest it will be |
@hboutemy, with the release of |
@msymons ok |
@hboutemy , apologies for the slow response. For me, there are several reasons for upgrading:
For what it's worth, I think there is a bunch of CycloneDX 1.5 functionality is currently missing and that could/should be supported by the plugin... but that's a separate concern. |
According to previous comments support for 1.6 should be unblocked. It's now months later and I'm wondering why 1.6 support hasn't been added yet. What can be done to help speed things along? |
On a whim I started making changes to support 1.6 here: https://github.com/thesurlydev/cyclonedx-maven-plugin/tree/support-1.6-spec I think there's more work to be done and I have questions about how releases are normally tested beyond the tests in the project. |
thanks @thesurlydev for the help, really appreciated, particularly given the good work done on being exhaustive on the impact on discovering new features of CDX 1.6 and how the plugin could be enhanced to benefit from them, this is even a wider question
honestly, we don't have any official strategy yet: until now, people use after the release then complain... :/ |
@msymons I'm very interested into having issues created for each CDX 1.5 (and now 1.6) feature that could be added, then on each issue a discussion on how to implement it in a reasonable way for normal users |
done in #556 by @thesurlydev : thanks a lot |
Version 1.6 of the CycloneDX spec has been released on 09 April 2024.
The spec is available at https://cyclonedx.org/docs/1.6/json/
The text was updated successfully, but these errors were encountered: