-
-
Notifications
You must be signed in to change notification settings - Fork 118
Add support for multiple input sources in SPDX and CycloneDX SBOMs generation #1911
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
…neration Signed-off-by: Om Santosh Suneri <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
See some comments for your consideration
| package_qs = get_queryset(project, "discoveredpackage") | ||
| package_qs = package_qs.prefetch_related("children_packages") | ||
|
|
||
| # Build a mapping of packages to their input sources when multiple inputs exist |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Create a function for that
| bom_ref=str(project.uuid), | ||
| ) | ||
|
|
||
| # Get input sources to potentially create components for them |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Make this a function
| self.assertResultsEqual(expected_file, output_file.read_text()) | ||
|
|
||
| def test_scanpipe_pipes_outputs_to_spdx_multiple_inputs(self): | ||
| """Test SPDX generation with multiple input sources.""" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| """Test SPDX generation with multiple input sources.""" |
|
|
||
| def test_scanpipe_pipes_outputs_to_cyclonedx_multiple_inputs(self): | ||
| """Test CycloneDX generation with multiple input sources.""" | ||
| project = make_project(name="MultiInputProject") |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Extract a function for the shared setup between these SPDX and CDX.
@tsteenbe
please review and request if any further changes are required !!