Skip to content

Is this valid SPDX? #212

@vargenau

Description

@vargenau

blackduck.spdx.txt

The attached file is adapted from SPDX in tag:value format generated by BlackDuck.

The Python tools tells that this is invalid SPDX.

pyspdxtools -i blackduck.spdx
ERROR:root:There have been issues while parsing the provided document:
Element Package is not the current element in scope, probably the expected tag to start the element (PackageName) is missing. Line: 26

I tend to agree with that, as the FilesAnalyzed clause does not follow the package.

But the Java tools say that the file is valid SPDX.

And the BlackDuck people claim that they cannot find something in the standard explaining why this is illegal.

So who is right?

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions