Skip to content

Usage of SpdxDocumentFile package manager and ort.yml #9904

Answered by tsteenbe
maennchen asked this question in Q&A
Discussion options

You must be logged in to vote

@maennchen project.spdx.yml and related package.spdx.yml were implemented in ORT as fallbacks for when ORT does not support a package manager or if there is no package manager e.g. C/C++ projects. These are specially crafted/reduced SPDX files that are valid by the SPDX spec v2.2 but I do not recommend you to use them as a base for an ORT integration. We have issue open to support SBOMs as first class input to ORT see #9878 but the issue is that if you take 6 SBOM tools you get 6 different SBOMs as neither in CycloneDX nor SPDX there is a test suite/guidelines that describes how to map a given reality in code into a SBOM.

The right way forwards for now in my opinion is for you to implemen…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@maennchen
Comment options

@maennchen
Comment options

Answer selected by maennchen
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants