Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Import/Export to SPDX documents #357

Open
kestewart opened this issue Jul 30, 2019 · 0 comments
Open

Import/Export to SPDX documents #357

kestewart opened this issue Jul 30, 2019 · 0 comments

Comments

@kestewart
Copy link

kestewart commented Jul 30, 2019

It would be very useful if grafeas could consume and generate SPDX documents (https://spdx.github.io/spdx-spec/) to enable sharing of information with other open source software bill of materials generation and scanning tools available, like TERN, FOSSology, Scancode.

Describe the solution you'd like
Please add option to enable grafeas to export and import SBoM document information from one of the valid and planned SPDX formats (tag:value, rdfa, xml, json, yaml).
There are libraries available to support subsets of these format in python and go are available in https://github.com/spdx

The SPDX project has some GSoC students working on improving some of the capabilities of the libraries over the summer so fall timeframe is a good window to deep dive on this is in file.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant