Conversation
Signed-off-by: Paul Horton <paul.horton@owasp.org>
Signed-off-by: Paul Horton <paul.horton@owasp.org>
Coverage summary from CodacySee diff coverage on Codacy
Coverage variation details
Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: Diff coverage details
Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: See your quality gate settings Change summary preferencesCodacy will stop sending the deprecated coverage status from June 5th, 2024. Learn more |
|
|
||
|
|
||
| @serializable.serializable_class | ||
| class CompositionReference: |
There was a problem hiding this comment.
❓
what is the purpose of this class?
why not use simple BomRef instances instead?
There was a problem hiding this comment.
Think there was a structural reason - let me check @jkowalleck
There was a problem hiding this comment.
Yes - it was added for structural reasons - happy to leave as is @jkowalleck ?
There was a problem hiding this comment.
i do not understand. what were these structural reasons?
I mean everybody ysing the library would ask the same question I did.
from the schema it looks like all these compositions.assembies and compositions.dependencies are simple sets of BomRef.
see https://github.com/CycloneDX/specification/blob/8e131b1688ccfe41e1bfdd4b3280f33dcc06d04c/schema/bom-1.6.schema.json#L2235-L2252
Signed-off-by: Paul Horton <paul.horton@owasp.org>
Signed-off-by: Paul Horton <paul.horton@owasp.org>
Signed-off-by: Paul Horton <paul.horton@owasp.org>
Adds support for
bom.compositionsas part of fulfilling #581.