Richard Laager <[email protected]> writes: > Files: testdata/valid-evidence.json > Copyright: OWASP Foundation > License: Apache-2.0 > Comment: > This file contains strings that are test copyright statements, which > are being used as a test vector for proper license/copyright parsing. > They do not correspond to any copyright of this package. > > That way, you are really explicit about which files have the issue.
Thank you Richard -- this seems reasonable, so I used it. https://salsa.debian.org/go-team/packages/golang-github-cyclonedx-cyclonedx-go/-/commit/515c349e1d8c0f1ba6dde892b7f1b79696f01ab3 /Simon
signature.asc
Description: PGP signature

