Validate Custom JSON-LD Context
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 45/100
Piste de recherche
Exécutez la commande Verify de l’issue sur sbom-output.spdx.json, puis comparez-le avec expanded-sbom-output.spdx.json produit par expand-custom-context.sh. Commencez par la validation du contexte JSON-LD de la commande Verify et déterminez comment les mappages de contexte personnalisés doivent être traités ; le travail est terminé lorsque le document original est validé sans nécessiter le script d’expansion externe.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
According to the Serialization Information section in the SPDX 3.0.1 spec serializing NamespaceMaps within the @context field for JSON-LD serializations is valid.
When serializing a physical SpdxDocument, any property of the logical element that can be natively represented within the chosen serialization format (e.g.,
@contextprefixes in JSON-LD instead of the namespaceMap) may utilize these native mechanisms. All remaining properties shall be serialized within the SpdxDocument element itself.
[...]
Additional namespace mappings may be defined within a separate object within the context.
The java spdx tools however do not currently support this.
Take for example the following document: sbom-output.spdx.json
export SPDX_TOOLS_VERSION=2.0.2
curl -sLO "https://github.com/spdx/tools-java/releases/download/v${SPDX_TOOLS_VERSION}/tools-java-${SPDX_TOOLS_VERSION}.zip"
unzip -j "tools-java-${SPDX_TOOLS_VERSION}.zip" "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar"
java -jar "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar" Verify "sbom-output.spdx.json"
The java tools fail with
This SPDX Document is not valid due to:
$.@context: must be the constant value 'https://spdx.org/rdf/3.0.1/spdx-context.jsonld'
even though the document should be valid.
An easy way to fix this would be to expand the custom context before processing the SPDX document.
See for example expand-custom-context.sh
./expand-custom-context.sh sbom-output.spdx.json
This small script expands the custom context and outputs expanded-sbom-output.spdx.json which successfully gets validated by the java tools.
java -jar "tools-java-${SPDX_TOOLS_VERSION}-jar-with-dependencies.jar" Verify "expanded-sbom-output.spdx.json"
This SPDX Document is valid.
It would be helpful if this behavior could be supported directly by the java-tools.
- Langage dominant
- Java
- Étoiles
- 100
- Forks
- 45
- Merge moyen
- 14 h 37 min
- PR mergées (30 j)
- 11
Préparer son environnement
- Fournit un Dockerfile ou un fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de spdx/tools-java
-
enhancement
Difficulté 4/5 3-5 jours Accessibilité débutants 45/100
spdx/tools-java#331 · 1 réaction ·
Les mainteneurs répondent en général sous 1 jour
-
bug spdx-2.3 validation
Difficulté 4/5 3-5 jours Accessibilité débutants 55/100
spdx/tools-java#316 · 1 commentaire · 1 réaction ·
Les mainteneurs répondent en général sous 1 jour
-
Release 2.0.8Ouverte
Difficulté 4/5 3-5 jours Accessibilité débutants 20/100
spdx/tools-java#313 · 1 réaction ·
Les mainteneurs répondent en général sous 1 jour
-
spdx-2.x spdx-3.x
Difficulté 3/5 1-2 jours Accessibilité débutants 58/100
spdx/tools-java#290 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
Warning when validatingOuvertevalidation
Difficulté 3/5 1-2 jours Accessibilité débutants 48/100
spdx/tools-java#287 · 1 commentaire · 1 réaction ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de spdx/tools-java
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 64/100
utopia-rise/godot-jvm#1004 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
spring-projects/spring-grpc#442 ·
-
Expose numberOfPermits in RateLimiterEvent.toString() and the ratelimiterevents actuator DTOOuverte
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
resilience4j/resilience4j#2547 ·
Les mainteneurs répondent en général sous 9 jours
-
Clock.MakeDate continues execution and returns a rolled-over instant after dispatching error on invalid datePeut-être pris Une pull request liée à cette issue est ouverte ou déjà fusionnée. Ouverte
Difficulté 1/5 Moins d'une heure Accessibilité débutants 82/100
mit-cml/appinventor-sources#4155 ·
Les mainteneurs répondent en général sous 1 jour
-
[Doc] - Creation du READMEOuverte
Difficulté 1/5 1-3 heures Accessibilité débutants 62/100
Hira-shi/PW1-DAI-Carrel-Egal-Eyer#28 ·
Les mainteneurs répondent en général sous 1 jour