Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support --normalize flag (sort+) for CycloneDX BOM on trim command output #81

Merged
merged 43 commits into from
Apr 26, 2024

Conversation

mrutkows
Copy link
Contributor

@mrutkows mrutkows commented Apr 5, 2024

This would be a first step to fully normalize all BOM structures (e.g., Components, Services, Vulns., ExternalRefs. Properties, etc.) which should help Diff and potential future Merge commands.

mrutkows added 30 commits April 5, 2024 17:39
Signed-off-by: Matt Rutkowski <[email protected]>
Signed-off-by: Matt Rutkowski <[email protected]>
Signed-off-by: Matt Rutkowski <[email protected]>
Signed-off-by: Matt Rutkowski <[email protected]>
@mrutkows mrutkows changed the title Sort CycloneDX BOM top-level arrays before diff Support --mormalize flag (sort+) for most CycloneDX BOM structures Apr 24, 2024
@mrutkows mrutkows changed the title Support --mormalize flag (sort+) for most CycloneDX BOM structures Support --normalize flag (sort+) for most CycloneDX BOM structures Apr 24, 2024
@mrutkows mrutkows changed the title Support --normalize flag (sort+) for most CycloneDX BOM structures Support --normalize flag (sort+) for CycloneDX BOM on Trim command output Apr 24, 2024
@mrutkows mrutkows self-assigned this Apr 24, 2024
@mrutkows
Copy link
Contributor Author

Please note that using BOMRef as an identifier for normalization is NOT correct as different iterations of BOMs generated by tools create random UIDs for many components.

@mrutkows mrutkows marked this pull request as ready for review April 26, 2024 17:33
@mrutkows mrutkows merged commit 6064e7c into main Apr 26, 2024
6 checks passed
@mrutkows mrutkows deleted the list-policy branch April 26, 2024 17:33
@mrutkows mrutkows changed the title Support --normalize flag (sort+) for CycloneDX BOM on Trim command output Support --normalize flag (sort+) for CycloneDX BOM on trim command output May 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant