You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The SPDX spec allows for multiple checksums to be provided for Packages and Files, but the current Package and File classes only allow a single value to be specified.
See the 'Cardinality' section of the following sections of the spec:
The text was updated successfully, but these errors were encountered:
Just adding a note here, from the SPDX Docfest on Sept. 16 -- looks like this issue leads to errors for valid SPDX documents if they include a FileChecksum with the mandatory SHA1, together with additional optional FileChecksums such as SHA256.
The SPDX spec allows for multiple checksums to be provided for Packages and Files, but the current Package and File classes only allow a single value to be specified.
See the 'Cardinality' section of the following sections of the spec:
The text was updated successfully, but these errors were encountered: