Die 21. 07. 20 et hora 08:44 Geyer-Blaumeiser Lars (IOC/PDL4) scripsit:
I like the idea, but just a thought. There is the new yaml format in SPDX 2.2, and we are thinking around using this format to mark certain folders as open source component,
That is a great idea.
But you’d really go make a full SPDX valid file for that? How? There are quite a few fields there that are obligatory.
One potential issue might be the hash value. For marking 3rd party code that’s a great boon, but for marking your own living code that might be a bit of a issue, if you need to change the hash value every time the code changes.
cheers, Matija