Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update spdx and osv libraries. #908

Merged
merged 4 commits into from Jun 6, 2023
Merged

Conversation

jeffmendoza
Copy link
Collaborator

The spdx tools library has changed to support multiple versions. Still just use v2.2, as that is what we were using before. We will need to update to handle multiple versions. Oddly there is a change in the parsed relationship output and testdata is updated.

Description of the PR

PR Checklist

  • All commits have a Developer Certificate of Origin (DCO) -- they are generated using -s flag to git commit.
  • All new changes are covered by tests
  • If GraphQL schema is changed, make generate has been run
  • If collectsub protobuf has been changed, make proto has been run
  • All CI checks are passing (tests and formatting)
  • All dependent PRs have already been merged

jeffmendoza and others added 4 commits June 6, 2023 10:58
The spdx tools library has changed to support multiple versions. Still just use
v2.2, as that is what we were using before. We will need to update to handle
multiple versions. Oddly there is a change in the parsed relationship output
and testdata is updated.

Signed-off-by: Jeff Mendoza <jlm@jlm.name>
Signed-off-by: Brandon Lum <lumjjb@gmail.com>
Signed-off-by: Jeff Mendoza <jlm@jlm.name>
@kodiakhq kodiakhq bot merged commit a2d5192 into guacsec:main Jun 6, 2023
8 checks passed
rmetzman pushed a commit to rmetzman/guac that referenced this pull request Jun 21, 2023
* Update spdx and osv libraries.

The spdx tools library has changed to support multiple versions. Still just use
v2.2, as that is what we were using before. We will need to update to handle
multiple versions. Oddly there is a change in the parsed relationship output
and testdata is updated.

Signed-off-by: Jeff Mendoza <jlm@jlm.name>

* update spdx struct use

Signed-off-by: Brandon Lum <lumjjb@gmail.com>

* Update to new spdx with bug fix and remove duplicate relationship.

Signed-off-by: Jeff Mendoza <jlm@jlm.name>

* Move to latest spdx.

Signed-off-by: Jeff Mendoza <jlm@jlm.name>

---------

Signed-off-by: Jeff Mendoza <jlm@jlm.name>
Signed-off-by: Brandon Lum <lumjjb@gmail.com>
Co-authored-by: Brandon Lum <lumjjb@gmail.com>
mlieberman85 pushed a commit to mlieberman85/artifact-ff that referenced this pull request Jul 5, 2023
* Update spdx and osv libraries.

The spdx tools library has changed to support multiple versions. Still just use
v2.2, as that is what we were using before. We will need to update to handle
multiple versions. Oddly there is a change in the parsed relationship output
and testdata is updated.

Signed-off-by: Jeff Mendoza <jlm@jlm.name>

* update spdx struct use

Signed-off-by: Brandon Lum <lumjjb@gmail.com>

* Update to new spdx with bug fix and remove duplicate relationship.

Signed-off-by: Jeff Mendoza <jlm@jlm.name>

* Move to latest spdx.

Signed-off-by: Jeff Mendoza <jlm@jlm.name>

---------

Signed-off-by: Jeff Mendoza <jlm@jlm.name>
Signed-off-by: Brandon Lum <lumjjb@gmail.com>
Co-authored-by: Brandon Lum <lumjjb@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants