feat: add `cyclonedx.model.dependency.Dependency.provides`
维护者通常 1 天内回复
评估
调研方向
从 cyclonedx.model.dependency.Dependency 和入口点 Bom.from_json(data=data) 开始;检查依赖字段是如何反序列化的。为 CycloneDX 1.6 示例中显示的 provides 字段添加支持,然后运行复现脚本,并确认 Bom.from_json 不再引发所报告的 ValueError。
由索引模型根据 Issue 内容生成。
描述
Library Version: 7.6.1
Description:
Steps to Reproduce:
- Use the example JSON provided in the CycloneDX bom-examples repository.
- Run the following script:
import json
from cyclonedx.model.bom import Bom
# source: https://github.com/CycloneDX/bom-examples/blob/c0436d86cd60693f01d19fe1aacfd01e70e17036/CBOM/Example-With-Dependencies/bom.json
sample = '''{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"serialNumber": "urn:uuid:3e671687-395b-41f5-a30f-a58921a69b79",
"version": 1,
"metadata": {
"component": {
"type": "application",
"bom-ref": "acme-application",
"name": "Acme Application",
"version": "1.0"
}
},
"components": [
{
"type": "cryptographic-asset",
"bom-ref": "aes128gcm",
"name": "AES",
"cryptoProperties": {
"assetType": "algorithm",
"algorithmProperties": {
"primitive": "ae",
"parameterSetIdentifier": "128",
"executionEnvironment": "software-plain-ram",
"implementationPlatform": "x86_64",
"certificationLevel": [ "none" ],
"mode": "gcm",
"cryptoFunctions": ["keygen", "encrypt", "decrypt", "tag"],
"classicalSecurityLevel": 128,
"nistQuantumSecurityLevel": 1
},
"oid": "2.16.840.1.101.3.4.1.6"
}
},
{
"type": "library",
"bom-ref": "crypto-library",
"name": "Crypto library",
"version": "1.0.0"
},
{
"type": "library",
"bom-ref": "some-library",
"name": "Some library",
"version": "1.0.0"
}
],
"dependencies": [
{
"ref": "acme-application",
"dependsOn": ["crypto-library"]
},
{
"ref": "crypto-library",
"provides": ["aes128gcm"],
"dependsOn": ["some-library"]
}
]
}'''
data = json.loads(sample)
Bom.from_json(data=data)
Observed Behavior:
The code fails with the following exception:
Traceback (most recent call last):
...
ValueError: Unexpected key provides/provides in data being serialized to cyclonedx.model.dependency.Dependency
Environment:
- Python version:
3.10 - Operating System:
macOS - Library version:
7.6.1
Let me know if this works!
- 主要语言
- Python
- 星标
- 117
- 派生
- 67
- 平均合并
- 21 小时 9 分钟
- 30 天内合并 PR
- 3
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
CycloneDX/cyclonedx-python-lib 的其他 Issue
-
[PERF] Quadratic (O(N^2)) serialization time for large BOMs — `Bom.validate()` → `register_dependency()` linear scan可能已有人在做 @inspired-geek 于 109 天前认领。 未关闭performance
难度 3/5 1-2 天 新手友好度 36/100
CycloneDX/cyclonedx-python-lib#1006 · 2 条评论 ·
维护者通常 1 天内回复
-
tests: test all model enums可能重新可做 @jkowalleck 于 125 天前认领,目前没有进行中的 PR。 未关闭QA
CycloneDX/cyclonedx-python-lib#991 · 已指派 1 人 ·
维护者通常 1 天内回复
-
feat(deps)!: make all de/serialization libraries optional可能重新可做 @Simoh23999 于 73 天前认领,目前没有进行中的 PR。 未关闭breaking change dependencies
难度 5/5 一周以上 新手友好度 35/100
CycloneDX/cyclonedx-python-lib#979 · 2 条评论 ·
维护者通常 1 天内回复
-
feat: Add support for Component signature可能已有人在做 @wiebe-vandendriessche 于 124 天前认领。 未关闭enhancement help wanted schema 1.4
难度 3/5 1-2 天 新手友好度 58/100
CycloneDX/cyclonedx-python-lib#978 · 4 条评论 ·
维护者通常 1 天内回复
-
chore: have coverage uploaded consitently可能重新可做 @jkowalleck 于 171 天前认领,目前没有进行中的 PR。 未关闭chore
CycloneDX/cyclonedx-python-lib#966 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 CycloneDX/cyclonedx-python-lib 的全部 Issue
相似的 Issue
-
namespace operations
难度 1/5 1 小时以内 新手友好度 72/100
EclipseFdn/open-vsx.org#14043 ·
维护者通常 1 天内回复
-
feedback simulation workshop
难度 2/5 1-3 小时 新手友好度 73/100
githubnext/gh-aw-workshop#4455 ·
维护者通常 1 天内回复
-
Triage 🩺
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复
-
[BUG] Container scenario crashes without expected_recovery_time, kube DNS example uses retry_wait未关闭needs-triage
难度 2/5 1-3 小时 新手友好度 77/100
krkn-chaos/krkn#1627 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
NousResearch/hermes-agent#136483 ·
维护者通常 1 天内回复