OpenChain-Project / Telco-WG

This is the OpenChain Telco Work Group
Other
12 stars 6 forks source link

Question about data format #57

Closed winterrocks closed 1 year ago

winterrocks commented 1 year ago

Question

In section https://github.com/OpenChain-Project/Telco-WG/blob/main/OpenChain%20Telco%20SBOM%20Specification.md#33-machine-readable-data-format the data format is tag:value, but in the future SPDX versions (3 --> ) it is possible that tag:value is no longer available and my understanding is that JSON will be the most widely used format. Would it make sense to change the format already for this spec to JSON?

Suggested Solution

Use JSON as a default format and refer to the conversions tools to do the conversions to better human readable formats.

stephenkilbaneadi commented 1 year ago

How likely is the discontinuation of Tag:Value? Personally, I'd prefer a structured value like JSON or XML, but I understand the value of Tag:Value being more readable, too.

winterrocks commented 1 year ago

Earlier I talked with Thomas Steenbergen and he said that it is likely that tag:value will be dropped for SPDX 3 and dropping it is also something that he is driving. At the moment I do not know if there has been any official decision done.

vargenau commented 1 year ago

Hi Jari and Stephen,

Thank you for your comments.

At the start of the specification, we decided to use SPDX 2.2, and not 2.3 because we wanted to use the ISO standard.

We also decided to use tag:value as we wanted to have a human-readable format. But in section 3.3 it is explained that you can also provide in addition other formats.

As for SPDX 3.0, it was decided that JSON will be the main format (or serialization as they say). What the other formats will be is not fully clear. In the slides that Kate Stewart presented recently at Open Source summit North America, the tag:value was still present.

We can discuss it in the meetings tomorrow.

Best regards,

Marc-Etienne

From: Jari Koivisto @.> Sent: Wednesday, June 7, 2023 8:41 PM To: OpenChain-Project/Telco-WG @.> Cc: Subscribed @.***> Subject: Re: [OpenChain-Project/Telco-WG] Question about data format (Issue #57)

Earlier I talked with Thomas Steenbergen and he said that it is likely that tag:value will be dropped for SPDX 3 and dropping it is also something that he is driving. At the moment I do not know if there has been any official decision done.

— Reply to this email directly, view it on GitHubhttps://github.com/OpenChain-Project/Telco-WG/issues/57#issuecomment-1581330711, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AAC4KKT3MYVAALQBYPFVYKLXKDDMJANCNFSM6AAAAAAY5PISWY. You are receiving this because you are subscribed to this thread.Message ID: @.**@.>>