Include hasFiles and documentDescribes information in relationship comparison
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 25/100
Línea de trabajo
Comienza con el método de comparación en tools-java e inspecciona cómo el serializador de tools-python representa hasFiles y documentDescribes. Compara la gestión de relaciones para ambos documentos de ejemplo, incluidas las entradas de relaciones invertidas u omitidas. Se considera terminado cuando los documentos semánticamente equivalentes se comparan como iguales sin informar incorrectamente de diferencias en las relaciones de documentos o archivos.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
I had a look into the comparison method in the tools-java to find out if we can also use them in the testbed. As this method originates from this repo, I decided to open the issue here. So, apart from the fact that we would need to change one namespace to compare two equal docs, I ran into another issue. This is also an issue within the testbed (#51).
When comparing the doument
SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
DocumentNamespace: https://some.namespace
DocumentName: document name
SPDXID: SPDXRef-DOCUMENT
## Creation Information
Creator: Tool: test-tool
Created: 2022-01-01T00:00:00Z
## Relationships
Relationship: SPDXRef-DOCUMENT DESCRIBES SPDXRef-fileA
Relationship: SPDXRef-DOCUMENT DESCRIBES SPDXRef-fileB
FileName: ./fileA.c
SPDXID: SPDXRef-fileA
FileChecksum: SHA1: d6a770ba38583ed4bb4525bd96e50461655d2758
LicenseConcluded: NOASSERTION
## Relationships
Relationship: SPDXRef-fileA DEPENDS_ON SPDXRef-fileB
Relationship: SPDXRef-fileA DESCRIBED_BY SPDXRef-DOCUMENT
FileName: ./fileB.c
SPDXID: SPDXRef-fileB
FileChecksum: SHA1: d6a770ba38583ed4bb4525bd96e50461655d2758
LicenseConcluded: NOASSERTION
## Relationships
Relationship: SPDXRef-fileB DEPENDENCY_OF SPDXRef-fileA
Relationship: SPDXRef-fileB DESCRIBED_BY SPDXRef-DOCUMENT
with
SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
DocumentNamespace: https://some.namespace2
DocumentName: document name
SPDXID: SPDXRef-DOCUMENT
## Creation Information
Creator: Tool: test-tool
Created: 2022-01-01T00:00:00Z
## Relationships
Relationship: SPDXRef-DOCUMENT DESCRIBES SPDXRef-fileA
Relationship: SPDXRef-DOCUMENT DESCRIBES SPDXRef-fileB
FileName: ./fileA.c
SPDXID: SPDXRef-fileA
FileChecksum: SHA1: d6a770ba38583ed4bb4525bd96e50461655d2758
LicenseConcluded: NOASSERTION
## Relationships
Relationship: SPDXRef-fileA DEPENDS_ON SPDXRef-fileB
Relationship: SPDXRef-fileA DESCRIBED_BY SPDXRef-DOCUMENT
FileName: ./fileB.c
SPDXID: SPDXRef-fileB
FileChecksum: SHA1: d6a770ba38583ed4bb4525bd96e50461655d2758
LicenseConcluded: NOASSERTION
## Relationships
Relationship: SPDXRef-fileB DEPENDENCY_OF SPDXRef-fileA
the resulting xlsx file lists a difference in the file relationships (which is understandable as the relationship Relationship: SPDXRef-fileB DESCRIBED_BY SPDXRef-DOCUMENT is missing -although it is a duplicate of SPDXRef-DOCUMENT DESCRIBES SPDXRef-fileB). But the result also marks document describes with diff although the values in the rows below are the same. The same holds for the file relationships of ./fileA.c.
Why is this marked as diff?
In general I would expect that the comparison is somehow independant from the direction of the relationship although I see that this is a rather complex topic and I can understand that the comparison would only be about the "actual present" relationships.
Another problem, which is related to this, is the following: For json, yaml and xml there are additionally the tags "documentDescribes" and "hasFiles" in packages to represent DESCRIBES, resp. CONTAINS-relationships. The tools-python avoid duplications when serialising and do not write for example SPDXRef-DOCUMENT DESCRIBES SPDXRef-File additionally out, because this information is already mapped in "documentDescribes: [SPDXRef-File]". This leads then with the comparison however again to the fact that two documents are not evaluated as equal.
Do you think it would make sense to add some additional logic to the comparison that checks for this kind of semantic equivalence of the relationships ( so including the information from hasFilesand documentDescribes) and not only for actual existence?
- Lenguaje dominante
- Java
- Estrellas
- 71
- Forks
- 44
- Merge medio
- 13 h 43 min
- PR fusionados (30 d)
- 9
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de spdx/Spdx-Java-Library
-
question
Dificultad 5/5 Más de una semana Aptitud para principiantes 30/100
spdx/Spdx-Java-Library#449 ·
-
question
Dificultad 5/5 Más de una semana Aptitud para principiantes 30/100
spdx/Spdx-Java-Library#398 ·
-
wontfix
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
spdx/Spdx-Java-Library#393 · 2 comentarios · 1 reacción ·
-
matching
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
spdx/Spdx-Java-Library#392 · 4 comentarios ·
-
enhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 30/100
spdx/Spdx-Java-Library#390 · 11 comentarios · 1 reacción ·
Todos los issues de spdx/Spdx-Java-Library
Issues similares
-
cbor
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
FasterXML/jackson-dataformats-binary#844 ·
Los mantenedores suelen responder en 1 día
-
improvement
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
apache/iceberg#18351 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
repowise-dev/repowise#2945 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Interpolating settings.xml can lead to malformed XML when variable value contains double-hyphenAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
apache/maven#13321 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
liquid-java/liquidjava#321 ·
Los mantenedores suelen responder en 2 días