Adding validate plumbing to consolidate verb by sfoslund · Pull Request #1115 · microsoft/sbom-tool (original) (raw)

@sfoslund

This PR adds some additional plumbing to the consolidate verb to parse the user provided ArtifactInfoMap and find all valid SBOMs that need to be validated/ consolidated. This PR has logic to account for a variety of flavors of SBOMs- spdx 2.2/3.0 and ADO/ CloudBuild

@sfoslund

DaveTryon

DaveTryon

sfoslund

DaveTryon

@sfoslund sfoslund marked this pull request as ready for review

June 27, 2025 16:54

DaveTryon

DaveTryon

DaveTryon

@sfoslund

@sfoslund

@github-actions

This PR changes files in the API project. Does it change any of the API interfaces in any way? Please note that this includes the following types of changes:

Because any of these changes can potentially break a downstream consumer with customized interface implementations, these changes need to be treated as breaking changes. Please do one of the following:

Option 1 - Publish this as a breaking change

  1. Update the documentation to show the new functionality
  2. Bump the major version in the next release
  3. Be sure to highlight the breaking changes in the release notes

Option 2 - Refactor the changes to be non-breaking

  1. Review this commit, which adds a new interface in a backward-compatible way
  2. Refactor the change to follow this pattern so that existing interfaces are left completely intact
  3. Bump the minor version in the next release

DaveTryon

@sfoslund

@sfoslund

@github-actions

This PR changes files in the API project. Does it change any of the API interfaces in any way? Please note that this includes the following types of changes:

Because any of these changes can potentially break a downstream consumer with customized interface implementations, these changes need to be treated as breaking changes. Please do one of the following:

Option 1 - Publish this as a breaking change

  1. Update the documentation to show the new functionality
  2. Bump the major version in the next release
  3. Be sure to highlight the breaking changes in the release notes

Option 2 - Refactor the changes to be non-breaking

  1. Review this commit, which adds a new interface in a backward-compatible way
  2. Refactor the change to follow this pattern so that existing interfaces are left completely intact
  3. Bump the minor version in the next release

DaveTryon

@sfoslund sfoslund deleted the sfoslund/validatePlumbing branch

June 27, 2025 19:51

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})