Re: Package, mandatory?
On Tue, Sep 26, 2017 at 7:11 AM, Jonas Oberg <jonas@...> wrote:
Prior to 2.0, the expectation was that there would only be a single package
with a set of files in each SPDX document.
When we introduced relationships/identifiers, in 2.0, we were able to extend the specification
to handle multiple packages could be present in the same SPDX document (cardinality (Many)).
Similarily it was recognized that an SPDX document could be just a grouping of files
(ie. a set of binary files and an artificial package to encompass them all was not needed). (hence
Optional). I can see though that we should have been clearer.
The tools should be able to handle the translation, so yes, go ahead and log a bug there too.
Bug in the spdx-tools, improvement in wording needed in the specification - so
please go ahead and log issues against both.