Add CycloneDX decoder - #811
Conversation
Signed-off-by: Keith Zantow <kzantow@gmail.com>
275e7c4 to
22d6d43
Compare
Signed-off-by: Keith Zantow <kzantow@gmail.com>
Signed-off-by: Keith Zantow <kzantow@gmail.com>
Signed-off-by: Keith Zantow <kzantow@gmail.com>
Signed-off-by: Keith Zantow <kzantow@gmail.com>
Signed-off-by: Keith Zantow <kzantow@gmail.com>
There was a problem hiding this comment.
The original intent of the formats package was to have the following structure:
├── common
│ ├── spdxhelpers/ # common spdx functions that to not reference model packages (only uses strings, ints, etc. ... primitives)
│ └── ...
└── spdx22json
├── decoder.go
├── encoder.go
├── format.go # wire up all functions to return a format object
├── model/
│ └── ... # the "format model" contains only struct definitions, no behavior
├── to_format_model.go # behavior to translate from syft sbom.SBOM to the format model
├── to_syft_model.go # behavior to translate from the format model to syft sbom.SBOM
└── validator.go
This pattern has quickly eroded with the introduction of 3rd party libs that are shared across multiple formats. This isn't a bad thing since we're getting a lot of functionality and models from these libs.
From the SPDX and CycloneDX work it seems like we're moving towards (using spdx randomly as an example):
├── common
│ └── spdxhelpers/ # do all of the model translation work for all spdx formats
│ ├── (all of the helpers)
│ ├── to_syft_model.go
│ └── to_format_model.go
└── spdx22json
├── decoder.go
├── encoder.go
├── format.go # wire up all functions to return a format object
└── validator.go
(I realize this PR isn't the first to start this, but I still wanted to point out the direction change.)
This PR is drifting in a slightly different direction (again, spdx choice here is arbitrary):
├── common
│ └── spdxhelpers/ # do all of the model translation work for all spdx formats
│ ├── (all of the helpers)
│ ├── decoder.go
│ ├── encoder.go
│ ├── to_syft_model.go
│ ├── to_format_model.go
│ └── validator.go
└── spdx22json
└── format.go # wire up all functions to return a format object
Here the spdx helpers are also making format choices by putting the encoder/decoders into the helpers package.
My ask: we should be consistent across formats when possible regarding these kinds of conventions. I think we should keep the encoder/decoders/validators in the respective format package and not in the helper packages.
Signed-off-by: Keith Zantow <kzantow@gmail.com>
Signed-off-by: Keith Zantow <kzantow@gmail.com>
|
From an earlier conversation about #811 (review) , let chat about this further in a followup PR (not blocking for this one). |
This PR adds support for decoding CycloneDX XML and JSON formats 🎉
This is a prerequisite for anchore/grype#481