Skip to content

Use Package-URL as spdxId if it is available #30

@bact

Description

@bact

When producing an SBOM, use Package-URL as spdxId if it is available for a software package.

This would help the element deduplication in SBOM fragments merging use case.

Note that Package-URL may not guaranteed to be unique (see spdx/spdx-spec#1379 (comment)), so we should only do this when the Package-URL is believed to be unique -- for example, fully qualified with exact major.minor.patch version number.

Track SPDX recommendation at:

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions