') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix: correctly handle object licenses in SBOM generation by jamietanna · Pull Request #6969 · npm/cli · GitHub
Skip to content

fix: correctly handle object licenses in SBOM generation - #6969

Merged
wraithgar merged 2 commits into
npm:latestfrom
jamietanna:defect/spdx-bom-license
Nov 6, 2023
Merged

fix: correctly handle object licenses in SBOM generation#6969
wraithgar merged 2 commits into
npm:latestfrom
jamietanna:defect/spdx-bom-license

Conversation

@jamietanna

Copy link
Copy Markdown
Contributor

As a means to resolve#6966, we can tweak the way we handle licenses,
where receiving a license object, instead of license string, results in
a malformed SPDX JSON SBOM.

While working on this, it was noted that CycloneDX also needed to be
amended, as it was omitting any license objects.

Closes#6966.

Also, document current license SPDX behaviour.

References

Closes#6966.

As a step towards resolving npm#6966, we should document how SPDX SBOM
generation works with a single string license or license expression.
Comment threadtest/lib/utils/sbom-cyclonedx.js Outdated
@jamietanna
jamietannaforce-pushed the defect/spdx-bom-license branch from bd12035 to e2134d5CompareNovember 6, 2023 16:07
@jamietanna

Copy link
Copy Markdown
ContributorAuthor

Should be able to re-run now 🤞

@jamietannajamietanna changed the title Fix: Correctly handle object licenses in SBOM generationfix: Correctly handle object licenses in SBOM generationNov 6, 2023
@jamietannajamietanna changed the title fix: Correctly handle object licenses in SBOM generationfix: correctly handle object licenses in SBOM generationNov 6, 2023
As a means to resolvenpm#6966, we can tweak the way we handle licenses,
where receiving a license object, instead of license string, results in
a malformed SPDX JSON SBOM.
While working on this, it was noted that CycloneDX also needed to be
amended, as it was omitting any license objects.
Closesnpm#6966.
@jamietanna
jamietannaforce-pushed the defect/spdx-bom-license branch from e2134d5 to 0d1d79fCompareNovember 6, 2023 16:45
@jamietanna

Copy link
Copy Markdown
ContributorAuthor

Sorry, that'll teach me not running the build locally 😞

@bdehamerbdehamer left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the fix.

@jamietanna

Copy link
Copy Markdown
ContributorAuthor

Very welcome, thanks for the support as it stands 👏🏽

@wraithgar
wraithgar merged commit 0f70088 into npm:latestNov 6, 2023
@wraithgar

Copy link
Copy Markdown
Contributor

@jamietanna if you want this backported to npm@9 you can cherry-pick the commit into a new PR made against the v9 branch

@github-actionsgithub-actionsBot mentioned this pull request Nov 6, 2023
@jamietanna
jamietanna deleted the defect/spdx-bom-license branch November 6, 2023 17:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] SBOM generation for SPDX generates invalid format for licenses - Invalid type. Expected: string, given: object

3 participants

@jamietanna@wraithgar@bdehamer