Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SW360.'Source Code Download URL' for Debian packages should be the dsc file #208

Closed
ericbl opened this issue Sep 17, 2024 · 3 comments
Closed
Assignees

Comments

@ericbl
Copy link

ericbl commented Sep 17, 2024

For Debian packages, the tool seems to set the .orig.tar.gz file into the 'Source Code Download URL' field of SW360.

It should be the 'dsc' file.

Let's take an example (Siemens internal):
https://sw360.siemens.com/group/guest/components/-/component/release/detailRelease/1fa4ed40b7e94fd2a5ffbd778499ca99#/tab-Summary
refers to the libssh2 package. According to the author of that release, your tool was used in their workflow to create or upload the component on sw360.
You see the orig.tar.gz set at 'Source Code Download URL'

The proper source file for that package is the corresponding dsc
Setting the dsc is what Gernot's tool is doing.

Please adapt your tool to set the dsc file and NOT the orig.tar.gz here.

Generally speaking, cross testing should be done between tools to ensure they set the same data.
See with Gernot for Debian specific topic, i.e. for Debian packages.

@gernot-h
Copy link
Member

Not sure if it's obvious which "Gernot" is meant, so in case of questions, feel free to contact me here or via Siemens channels. ;-)

@sumanthkb44
Copy link
Collaborator

sumanthkb44 commented Oct 17, 2024

@ericbl Thanks for looking out our tool.

Will check with the Clearing team (@WagnerMarco ) and will adopt the changes accordingly.

@sumanthkb44 sumanthkb44 self-assigned this Oct 17, 2024
@sumanthkb44
Copy link
Collaborator

@ericbl Thanks for the suggestions,

We had a discussion with @WagnerMarco & @gernot-h
Will try to incorporate this in our feature release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants