Skip to content

feat: Add missing provides mapping to Dependency to comply with CycloneDX 1.6 spec - #599

Merged
nscuro merged 3 commits into
CycloneDX:masterfrom
vibe13:add_provides_mapping
Oct 6, 2026
Merged

nscuro merged 3 commits into
CycloneDX:masterfrom
vibe13:add_provides_mapping

Conversation

@vibe13

@vibe13 vibe13 commented Jan 28, 2025

Copy link
Copy Markdown
Contributor

Following #565, this PR attempts to add the missing mapping to comply with the CycloneDX 1.6 spec for the "provides" field inside the Dependency object: https://cyclonedx.org/docs/1.6/json/#dependencies_items_provides.

@vibe13
vibe13 requested a review from a team as a code owner January 28, 2025 13:56
@vibe13
vibe13 force-pushed the add_provides_mapping branch from c05258b to d42bf3b Compare January 28, 2025 13:57
@vibe13
vibe13 force-pushed the add_provides_mapping branch from d42bf3b to 62a4ffc Compare February 11, 2025 10:47
Comment thread src/main/java/org/cyclonedx/model/Dependency.java Outdated
Comment thread src/main/java/org/cyclonedx/model/Dependency.java Outdated
Comment thread src/main/java/org/cyclonedx/util/serializer/DependencySerializer.java Outdated
@vibe13
vibe13 force-pushed the add_provides_mapping branch from a358c91 to 4e13d3a Compare March 29, 2025 13:33
@vibe13

vibe13 commented Mar 29, 2025

Copy link
Copy Markdown
Contributor Author

@mr-zepol Hi, apologies for the very late reply, pushed some fixes after your review, thanks!

@vibe13

vibe13 commented May 12, 2025

Copy link
Copy Markdown
Contributor Author

@mr-zepol Hi! Is there anything else I can do here? Would it be possible to have another review? Thanks!

@rsvoboda

rsvoboda commented Oct 5, 2026

Copy link
Copy Markdown

@mr-zepol / @nscuro / @stevespringett can you get back to this please?

@nscuro

nscuro commented Oct 5, 2026

Copy link
Copy Markdown
Member

I don't see any remaining issues. @vibe13, can you resolve the merge conflicts please?

@nscuro nscuro added the enhancement New feature or request label Oct 5, 2026
vibe13 added 3 commits October 6, 2026 11:14
…neDX 1.6 spec

Signed-off-by: Andrea Vibelli <avibelli@redhat.com>
Signed-off-by: Andrea Vibelli <avibelli@redhat.com>
…alizer

- Replace broken writeXMLProvides (used writeFieldName+writeStartArray
  causing 'Can not write a field name, expecting a value') with the same
  processNamespace pattern used for sub-dependency elements
- Extend the writeStartArray/writeEndArray guard in writeXMLDependency to
  cover provides children, not only sub-dependency children; without this,
  a dependency with only provides (no sub-deps) would fail with 'Can not
  start an object, expecting field name'
- Replace CollectionUtils.isNotEmpty() calls (removed upstream dependency)
  with inline null+isEmpty checks

Signed-off-by: Andrea Vibelli <avibelli@redhat.com>
@vibe13
vibe13 force-pushed the add_provides_mapping branch from 4e13d3a to d76cbb2 Compare October 6, 2026 10:20
@codacy-production

codacy-production Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 13 complexity

Metric Results
Complexity 13

View in Codacy

🟢 Coverage 80.65% diff coverage · +0.01% coverage variation

Metric Results
Coverage variation ✅ +0.01% coverage variation
Diff coverage ✅ 80.65% diff coverage

View coverage diff in Codacy

Coverage variation details
Coverable lines Covered lines Coverage
Common ancestor commit (cf5d168) 7831 5861 74.84%
Head commit (d76cbb2) 7859 (+28) 5883 (+22) 74.86% (+0.01%)

Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: <coverage of head commit> - <coverage of common ancestor commit>

Diff coverage details
Coverable lines Covered lines Diff coverage
Pull request (#599) 31 25 80.65%

Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: <covered lines added or modified>/<coverable lines added or modified> * 100%

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@vibe13

vibe13 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

@nscuro @rsvoboda done!

@nscuro
nscuro merged commit 7fceac4 into CycloneDX:master Oct 6, 2026
8 checks passed
@vibe13

vibe13 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants