Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Validate Custom JSON-LD Context

Ouverte
#263 2 commentaires 1 réaction 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
45/100
Type d'issue
Fonctionnalité
Clarté
Plutôt claire
Activité
À l'abandon
Stack technique
java
Domaine
cli, tooling

Piste de recherche

Exécutez la commande Verify de l’issue sur sbom-output.spdx.json, puis comparez-le avec expanded-sbom-output.spdx.json produit par expand-custom-context.sh. Commencez par la validation du contexte JSON-LD de la commande Verify et déterminez comment les mappages de contexte personnalisés doivent être traités ; le travail est terminé lorsque le document original est validé sans nécessiter le script d’expansion externe.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

enhancement

According to the Serialization Information section in the SPDX 3.0.1 spec serializing NamespaceMaps within the @context field for JSON-LD serializations is valid.

When serializing a physical SpdxDocument, any property of the logical element that can be natively represented within the chosen serialization format (e.g., @context prefixes in JSON-LD instead of the namespaceMap) may utilize these native mechanisms. All remaining properties shall be serialized within the SpdxDocument element itself.
[...]
Additional namespace mappings may be defined within a separate object within the context.

The java spdx tools however do not currently support this.
Take for example the following document: sbom-output.spdx.json

export SPDX_TOOLS_VERSION=2.0.2
curl -sLO "https://github.com/spdx/tools-java/releases/download/v${SPDX_TOOLS_VERSION}/tools-java-${SPDX_TOOLS_VERSION}.zip"
unzip -j "tools-java-${SPDX_TOOLS_VERSION}.zip" "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar"
java -jar "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar" Verify "sbom-output.spdx.json"

The java tools fail with

This SPDX Document is not valid due to:
        $.@context: must be the constant value 'https://spdx.org/rdf/3.0.1/spdx-context.jsonld'

even though the document should be valid.

An easy way to fix this would be to expand the custom context before processing the SPDX document.
See for example expand-custom-context.sh

./expand-custom-context.sh sbom-output.spdx.json

This small script expands the custom context and outputs expanded-sbom-output.spdx.json which successfully gets validated by the java tools.

java -jar "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar" Verify "expanded-sbom-output.spdx.json"
This SPDX Document is valid.

It would be helpful if this behavior could be supported directly by the java-tools.

Langage dominant
Java
Étoiles
100
Forks
45
Merge moyen
14 h 37 min
PR mergées (30 j)
11

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de spdx/tools-java

Toutes les issues de spdx/tools-java

Issues similaires

Plus d'issues Java

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.