Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] typo ? #136

Open
MasahiroDAIKOKU opened this issue Dec 6, 2024 · 7 comments
Open

[Question] typo ? #136

MasahiroDAIKOKU opened this issue Dec 6, 2024 · 7 comments
Assignees
Labels
question Further information is requested

Comments

@MasahiroDAIKOKU
Copy link
Contributor

Question

In section 3.5, there is the following statement

SBOMs conforming to the OpenChain Telco SBOM Guide MUST contain information … to which version of the software they were created (using the SPDX CreatorComment field).

Does this mean the SPDX Creator field?

@MasahiroDAIKOKU MasahiroDAIKOKU added the question Further information is requested label Dec 6, 2024
@vargenau
Copy link
Collaborator

vargenau commented Dec 6, 2024 via email

@MasahiroDAIKOKU
Copy link
Contributor Author

Thank you for your reply.

If the description specifying the SBOM creating tool does not follow the “toolidentifier-version” syntax described in the Creator field of section 6.10 of the SPDX specification, the Creator comment field may be used as in the example in section 3.5.2 of the SBOM Guide.

Is this correct?

@vargenau
Copy link
Collaborator

vargenau commented Dec 9, 2024 via email

@MasahiroDAIKOKU
Copy link
Contributor Author

MasahiroDAIKOKU commented Dec 13, 2024

Hi Marc-san,

Thank you very much for your kind reply, it is very much appreciated.
I understood it as follows.

If the syntax of the Creator field "Creator: Tool: toolidentifier-version" as defined in the SPDX specification cannot be complied with, strict compliance with the syntax is not mandatory.
In that case, the syntax described in "3.5.2 Rationale" can be used instead of complying with the ‘Creator: Tool: toolidentifier-version’ of the Creator field as described in the SPDX specification.

How about adding the following text to section 3.5.2 to make it easier to understand for readers with limited understanding, including myself?

"The following description is also acceptable as a value for the Creator field."

@MasahiroDAIKOKU
Copy link
Contributor Author

Hi Marc-san,

I ran the open-chain-sbom-validator with the three examples described in Section 3.5.2.
As a result, the second and third examples did not output an error in the tool, but the first example "Creator: Tool: sigs.k8s.io/bom/pkg/spdx" did output an "Missing or invalid field in CreationInfo::Creator" error type message.
I apologize if I have made a mistake in the operation.

@vargenau
Copy link
Collaborator

vargenau commented Jan 9, 2025 via email

@MasahiroDAIKOKU
Copy link
Contributor Author

Hi Marc-san and Csatari-san,
As I showed you at Zoom, it is version 0.1.7.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

3 participants