Skip to content

JSON to XML conversion: Hyphen in 'PACKAGE-MANAGER' replaced with Underscore #849

Description

@NorioKobota

"PACKAGE-MANAGER" string used in External Reference field is converted from JSON format to XML/YAML format, and '-' is converted to '_'.
https://spdx.github.io/spdx-spec/v2.3/package-information/#721-external-reference-field

Activity

  1. mneumei commented on Apr 30, 2025

    @mneumei

    This means the current version is not conformant with the spdx 2.3 standard, right?

    From what i see, this could be solved by replacing _ with - for the category name in here:

    elif external_ref_property == ExternalPackageRefProperty.REFERENCE_CATEGORY:

  2. meretp commented on May 15, 2025

    @meretp
    Collaborator

    This is a common issue that keeps popping up (see #813), but this is an issue with the spec as you can see in this discussion spdx/spdx-spec#792, not with the tooling. The spec only specifies the dash for tag value output which is also what the tooling writes, for JSON/YAML/XML the spec also allows underscore, we decided to support both (underscore and hyphen) when parsing data from JSON/YAML/XML but only write one, i.e., underscores with our tooling.

  3. mneumei commented on May 16, 2025

    @mneumei

    In the #792 discussions it is also mentioned that the spec is now only containing dash (spdx/spdx-spec@214f23d). This means that if people go strictly after the schema, the produced sbom is invalid. So basically every tool along the way has to implement the bugfix in order to read this sbom. The fix would make it compliant to the scheme.

  4. meretp commented on May 16, 2025

    @meretp
    Collaborator

    My understanding of the discussion is that the "only dash spec" was a bug in the spec and both options should be valid. However for v2.2 only the underscore was valid (https://github.com/spdx/spdx-spec/blob/development/v2.2/schemas/spdx-schema.json) and as this tooling should support as much as possible using the underscore is a valid choice. I am still not convinced that this needs to be fixed as also the discussions state that tooling should support both versions when parsing data (spdx/spdx-spec#792 (comment)).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions