Hi Bill,
The proposed approach is useful. I will try it out in practice.
Just have one question in regards to:
When releasing an SPDX document for external consumption, its basename
must be unique within the namespace of the producing organization.
(e.g. http://acme.com/spdx/mypackage-1-2.spdx where the organization
will not publish another file with basename 'mypackage-1-2.spdx' )
I have cases where the document is included on the distribution package
but where the owners are not willing to make it available to public
(just privately to selected companies).
Meaning, a network location isn't possible as namespace. I'm currently
referring to other SPDX documents within the folder structure as
solution.
To keep the URI scheme possible and reference documents within the
folders, would something like this be possible?
file:///./spdx/mypackage-1-2.spdx
Or perhaps I misunderstood the intention of namespaces. My thanks in
advance.
With kind regards,
Nuno Brito
---
email: [email protected]
phone: +49 615 146 03187
_______________________________________________
Spdx-tech mailing list
[email protected]
https://lists.spdx.org/mailman/listinfo/spdx-tech