如何将SPDX 1.2版本RDF格式文件转换为SPDX 2.3版本?
将SPDX 1.2版本RDF文件转换为SPDX 2.3版本的实现方法
问题背景
我有一份SPDX 1.2版本的RDF/XML文件,需要转换为SPDX 2.3版本。使用Python的spdx-tools工具时,最初解析原文件遇到错误:spdx_tools.spdx.parser.error.SPDXParsingError: ["Error while parsing CreationInfo: ['No creators provided.']"],但文件中已定义creator字段。
原SPDX 1.2 RDF文件内容
<?xml version="1.0" encoding="utf-8"?> <rdf:RDF xmlns:spdx="http://spdx.org/rdf/terms#" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:doap="http://usefulinc.com/ns/doap#" xmlns:ptr="http://www.w3.org/2009/pointers#" xmlns:rdfs="http://www.w3.org/2000/01/rdf-schema#"> <spdx:SpdxDocument rdf:about="http://www.spdx.org/tools#SPDXRef-DOCUMENT"> <specVersion>SPDX-1.2</specVersion> <dataLicense rdf:resource="http://spdx.org/licenses/CC0-1.0"/> <rdfs:comment> This document was created using SPDX 1.2 using licenses from the web site. </rdfs:comment> <spdx:creationInfo> <spdx:CreationInfo> <creator>Person: Me</creator> <creator>Organization: Company</creator> <creator>Tool: XYZ </creator> <created>2024-01-27T18:30:22Z</created> <rdfs:comment>SBOM SPDX1.2 Template</rdfs:comment> </spdx:CreationInfo> </spdx:creationInfo> <spdx:describesPackage> <spdx:Package> <spdx:name>First_Package</spdx:name> <spdx:versionInfo>01.01.01</spdx:versionInfo> <spdx:supplier> Me</spdx:supplier> <spdx:downloadLocation> DirectDelivery </spdx:downloadLocation> <packageVerificationCode> <PackageVerificationCode> <packageVerificationCodeValue>7fe30480b4798198be295f083f1022c983bcd34d</packageVerificationCodeValue> </PackageVerificationCode> </packageVerificationCode> <sourceInfo>cpe:2.3:a:Me:SW CP:01.01.01:*:*:*:*:*:*:*</sourceInfo> <licenseConcluded rdf:resource="http://spdx.org/licenses/LGPL-2.0" /> <licenseInfoFromFiles rdf:resource="http://spdx.org/licenses/GPL-2.0" /> <licenseDeclared rdf:resource="http://spdx.org/licenses/LGPL-2.0" /> <copyrightText> Copyright 2024 Me </copyrightText> </spdx:Package> </spdx:describesPackage> <spdx:referencesFile></spdx:referencesFile> </spdx:SpdxDocument> </rdf:RDF>
修正后的可解析SPDX 1.2文件
经调整后,文件可被spdx-tools 0.7.1及0.8.2版本成功解析,调整点包括:
- 为所有未加命名空间的元素添加
spdx:前缀(如specVersion→spdx:specVersion、creator→spdx:creator等) - 给Package元素添加唯一标识符
rdf:about - 将
downloadLocation的DirectDelivery替换为SPDX标准值spdx#noassertion - 补充了
referencesFile的具体文件内容 - 添加了SPDX 1.2标准未规定的
spdx:name字段(工具解析所需)
修正后的文件内容:
<?xml version="1.0" encoding="utf-8"?> <rdf:RDF xmlns:spdx="http://spdx.org/rdf/terms#" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:doap="http://usefulinc.com/ns/doap#" xmlns:ptr="http://www.w3.org/2009/pointers#" xmlns:rdfs="http://www.w3.org/2000/01/rdf-schema#"> <spdx:SpdxDocument rdf:about="http://www.spdx.org/tools#SPDXRef-DOCUMENT"> <spdx:specVersion>SPDX-1.2</spdx:specVersion> <spdx:name>SPDX-Tools-Test</spdx:name> <spdx:dataLicense rdf:resource="http://spdx.org/licenses/CC0-1.0"/> <rdfs:comment> This document was created using SPDX 1.2 using licenses from the web site. </rdfs:comment> <spdx:creationInfo> <spdx:CreationInfo> <spdx:creator>Person: Me</spdx:creator> <spdx:creator>Organization: Company</spdx:creator> <spdx:creator>Tool: XYZ</spdx:creator> <spdx:created>2024-01-27T18:30:22Z</spdx:created> <rdfs:comment>SBOM SPDX1.2 Template</rdfs:comment> </spdx:CreationInfo> </spdx:creationInfo> <spdx:describesPackage> <spdx:Package rdf:about="http://www.spdx.org/tools#SPDXRef-Package"> <spdx:name>First_Package</spdx:name> <spdx:versionInfo>01.01.01</spdx:versionInfo> <spdx:supplier>Person: Me</spdx:supplier> <spdx:downloadLocation>spdx#noassertion</spdx:downloadLocation> <spdx:packageVerificationCode> <spdx:PackageVerificationCode> <spdx:packageVerificationCodeValue>7fe30480b4798198be295f083f1022c983bcd34d</spdx:packageVerificationCodeValue> </spdx:PackageVerificationCode> </spdx:packageVerificationCode> <spdx:sourceInfo>cpe:2.3:a:Me:SW CP:01.01.01:*:*:*:*:*:*:*</spdx:sourceInfo> <spdx:licenseConcluded rdf:resource="http://spdx.org/licenses/LGPL-2.0" /> <spdx:licenseInfoFromFiles rdf:resource="http://spdx.org/licenses/GPL-2.0" /> <spdx:licenseDeclared rdf:resource="http://spdx.org/licenses/LGPL-2.0" /> <spdx:copyrightText> Copyright 2024 Me </spdx:copyrightText> </spdx:Package> </spdx:describesPackage> <spdx:referencesFile> <spdx:File rdf:about="http://www.spdx.org/tools#SPDXRef-File"> <spdx:fileName> ./First_Package/file.c </spdx:fileName> <spdx:checksum> <spdx:Checksum> <spdx:algorithm rdf:resource="http://spdx.org/rdf/terms#checksumAlgorithm_sha1"/> <spdx:checksumValue>c2b4e1c67a2d28fced849ee1bb76e7391b93f125</spdx:checksumValue> </spdx:Checksum> </spdx:checksum> </spdx:File> </spdx:referencesFile> </spdx:SpdxDocument> </rdf:RDF>
需求:将解析后的SPDX 1.2模型转换为SPDX 2.3版本文件
目前已完成SPDX 1.2文件的解析,需要基于解析得到的数据模型生成SPDX 2.3版本的文件,寻求具体实现方法。
内容的提问来源于stack exchange,提问作者crizzo
相关产品推荐
相关产品推荐

