Skip to content

fix: emit independently validated SPDX 2.3 evidence - #31

Merged
codeforester merged 1 commit into
mainfrom
bug/22-20260917-bug-validate-beacon-sboms-with-an-independent-spdx-2-3-valid
Sep 17, 2026
Merged

codeforester merged 1 commit into
mainfrom
bug/22-20260917-bug-validate-beacon-sboms-with-an-independent-spdx-2-3-valid

Conversation

@codeforester

Copy link
Copy Markdown
Contributor

Summary

Generate SPDX 2.3 file checksums with SHA1 plus SHA256, coherent package verification codes, source identities, and CONTAINS/DEPENDS_ON relationships. Require pinned spdx-tools 0.8.5 semantic validation in local and hosted artifact tests. The generator remains standard-library-only and offline.

Validation

Full ./tests/validate.sh passed (27 BATS cases). Independent validate_full_spdx_document returned zero messages. UTC/Asia-Kolkata artifact sets match; standalone verification passed.

Fixes #22

@codeforester
codeforester merged commit bf0fc4c into main Sep 17, 2026
12 checks passed
@codeforester
codeforester deleted the bug/22-20260917-bug-validate-beacon-sboms-with-an-independent-spdx-2-3-valid branch September 17, 2026 16:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: validate Beacon SBOMs with an independent SPDX 2.3 validator

1 participant