Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Add SPDX header to SpringQL souce files #143

Open
thatsdone opened this issue May 14, 2022 · 1 comment
Open

feat: Add SPDX header to SpringQL souce files #143

thatsdone opened this issue May 14, 2022 · 1 comment
Labels
feat New feature or request

Comments

@thatsdone
Copy link

Is your feature request related to a problem? Please describe.

I'm not sure if this is a feature request or not, but anyway I thought it's a good idea to consider
adding SPDX header lines to SpringQL source code files
so that SpringQL can get ready for SBOM (Software BOM) management requirements
in various industries (such as automotive).

Describe the solution you'd like

Simply add SPDX header lines.

For example, in case of Linux kernel, you can find an example at the top line of kernel/sched/sched.h:

https://github.com/torvalds/linux/blob/master/kernel/sched/sched.h#1

Describe alternatives you've considered

There are various discussions regarding SBOM.
For example,

https://www.openbom.com/blog/software-bill-of-materials-bom-3-reasons-manufacturing-companies-should-start-managing-sbom-in-2021

But, anyway SPDX activity is under the umbrella of the Linux Foundation,

https://spdx.dev/

and it's a part of ISO standard since September 2021:

https://spdx.dev/spdx-specification-is-now-an-iso-standard/

So, I think SPDX is an enough reasonable choice.

@thatsdone thatsdone added the feat New feature or request label May 14, 2022
@laysakura
Copy link
Contributor

@thatsdone Thank you for your suggestion. We would like to support it.

We believe dependency management should be critically important for system softwares in auto motives and we agree with agree with the objectives of SBOM.

I'm not sure if this is a feature request or not

This should be new feature for SpringQL's users since they can manage the dependency to SpringQL following the SPDX spec.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feat New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants