-
Notifications
You must be signed in to change notification settings - Fork 38
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft: Support multiple purl identifiers in product_identification_helper #781
base: master
Are you sure you want to change the base?
Conversation
I'm unsure how to modify the examples to get the final text to build. When I run the make command, I get:
|
This allows a vendor to specify multiple purl identifiers for a single component (present as a product version branch in the product tree). Multiple purls may identify the same component but point to different locations from where that component may be available. Thus, it is mandatory that if multiple purls are present in a single product_identification_helper object, they must only differ in their qualifiers. Otherwise they should be set up as different product tree branches.
abefd8e
to
757ee67
Compare
"hashes": { | ||
"hashes": [ | ||
// ... | ||
}, | ||
"model_numbers": { | ||
], | ||
"model_numbers": [ | ||
// ... | ||
}, | ||
"purl": { | ||
], | ||
"purls": [ | ||
// ... | ||
}, | ||
"sbom_urls": { | ||
], | ||
"sbom_urls": [ | ||
// ... | ||
}, | ||
"serial_numbers": { | ||
], | ||
"serial_numbers": [ | ||
// ... | ||
}, | ||
"skus": { | ||
], | ||
"skus": [ | ||
// ... | ||
}, | ||
"x_generic_uris": { | ||
], | ||
"x_generic_uris": [ | ||
// ... | ||
} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should do that in a separate commit to keep the feature changes separate from the editorial ones.
@mprpic Thank you for the Draft. I didn't had time yet to do a complete review but here are some quick comments:
|
This allows a vendor to specify multiple purl identifiers for a single component (present as a product version branch in the product tree). Multiple purls may identify the same component but point to different locations from where that component may be available. Thus, it is mandatory that if multiple purls are present in a single
product_identification_helper object, they must only differ in their qualifiers. Otherwise they should be set up as different product tree branches.
Resolves #774