for consideration in adding to spec/enumeration model

====== Sameer's list ======

Hi:

The following are the file dependency types, which can be utilized:

·         ### BuildFrom
·         ### BuildScript
·         ### SPDXFile
·         ### MetaFile
·         ### SourceOffer  (let's document this important Use Case)

Regards,
Sameer

A few observations:
·         We don't have a use case for the SourceOffer.  I think it is a great 
use case to add - I can certainly utility in being able to use SPDX documents 
to track the relationship between a binary file and the required source files 
needing to be redistributed.
·         I believe BuildFrom is equivalent to generatedFrom
·         I believe BuildScript is equivalent to usageType buildTools
·         Will we still need a MetaFile  and SPDXFilerelationship in SPDX 2.0?  
The package and SPDX document relationships should satisfy this need (I think).

Gary



==== in Bill's java / jar re-use diagram ========

builtFrom
artifactOf
patchOf
upstreamBinary

burst  (for archives, unpacking the contents within…)
exploded


=========== in Debian Policy Manual =======

7.2 Binary Dependencies - Depends, Recommends, Suggests, Enhances, Pre-Depends

7.3 Packages which break other packages - Breaks

7.4 Conflicting binary packages - Conflicts

7.5 Virtual packages - Provides

7.6 Overwriting files and replacing packages - Replaces

7.7 Relationships between source and binary packages - Build-Depends, 
Build-Depends-Indep, Build-Conflicts, Build-Conflicts-Indep

7.8 Additional source packages used to build the binary - Built-Using

_______________________________________________
Spdx-tech mailing list
[email protected]
https://lists.spdx.org/mailman/listinfo/spdx-tech

Reply via email to