Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ambiguity in SPDX documentation in relation b/w files and filesAnalyzed fields #316

Open
Moullisha opened this issue Dec 13, 2023 · 1 comment

Comments

@Moullisha
Copy link

As per the below code snippet, if filesAnalyzed is true, files array must contain any files related to the package.
No clear correlation between the files and the filesAnalyzed field has been mentioned in the SPDX document.

image

@Moullisha Moullisha changed the title files required when filesAnalayzed is true but same has not been specified in SPDX document. Ambiguity in SPDX documentation in relation b/w files and filesAnalyzed fields Dec 13, 2023
@goneall
Copy link
Member

goneall commented Dec 13, 2023

@Moullisha - We are switching over to a new version of the utility https://github.com/spdx/tools-java and the library https://github.com/spdx/spdx-java-library

Could you check and see if the same issue is in the new version? It's unlikely this utility will be updated except for critical security issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants