Skip to content

Conversation

@mhorner-vera
Copy link
Contributor

Since CycloneDX v1.4, version is no longer a required field: https://cyclonedx.org/docs/1.4/json/#components_items_version

We also made the determination in Slack to just skip components that have a missing PURL. This patch has made an exception only for the missing PURL case, and no others. If we want to relax our input requirements further, we can discuss that here.

@mhorner-vera mhorner-vera requested a review from a team as a code owner March 27, 2025 17:52
@CLAassistant
Copy link

CLAassistant commented Mar 27, 2025

CLA assistant check
All committers have signed the CLA.

@mhorner-vera mhorner-vera requested a review from cd-work March 27, 2025 17:52
Copy link
Contributor

@cd-work cd-work left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just to be clear: The PURL is also optional according to the spec?

Co-authored-by: Christian Duerr <102963075+cd-work@users.noreply.github.com>
@mhorner-vera
Copy link
Contributor Author

Just to be clear: The PURL is also optional according to the spec?

Yes

@mhorner-vera mhorner-vera requested a review from cd-work March 27, 2025 18:43
@mhorner-vera mhorner-vera enabled auto-merge (squash) March 27, 2025 20:33
@mhorner-vera mhorner-vera merged commit edf887f into main Mar 27, 2025
17 checks passed
@mhorner-vera mhorner-vera deleted the mathew/fix-cyclonedx-parser branch March 27, 2025 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants