Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merging two reports together #62

Open
Jeeppler opened this issue Jun 23, 2022 · 4 comments
Open

Merging two reports together #62

Jeeppler opened this issue Jun 23, 2022 · 4 comments

Comments

@Jeeppler
Copy link

Is this tool able to merge to reports together. For example, Report-A.spdx and Report-B.spdx`?

@goneall
Copy link
Member

goneall commented Jun 23, 2022

@Jeeppler Not currently. It wouldn't be too difficult to create the feature, but I probably won't have time to work on it until after the SPDX 2.3 release changes are complete.

If you and Java experience and want to contribute changes to support this functionality, I can give you some pointers to get you started.

@spatil00
Copy link

spatil00 commented Aug 9, 2022

I am not sure how it will work. If you have two SBoM from different components , each will have their own headers ( Document Creation section in SPDX specification) , I am not sure if SPDX specification gives options to keep headers for two components ?

@goneall
Copy link
Member

goneall commented Aug 9, 2022

@spatil00 I was thinking you could create a new SPDX document with it's own document creation section but include relationships from the new documents to the old documents. You could create External Document References for the 2 original docs. A relationship type DESCENDANT_OF and/or AMENDS could be used to describe the new SPDX document is derived from the 2 original documents. A relationship type of COPY_OF could be used to refer back to the original package/file/snippets from the original package if you want to make the entire operation traceable.

@rnjudge
Copy link

rnjudge commented Mar 20, 2023

@Jeeppler check out https://github.com/vmware-samples/sbom-composer for combining SPDX docs. This is in the process of being moved under the OpenSSF.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants