Details
-
Suggestion
-
Resolution: Unresolved
-
P3: Somewhat important
-
None
-
6.8.1
-
None
-
bc3bbb51b (dev), 82dc92cb1 (dev), 21815ae5e (6.9), fafb4f11e (6.9), 5c833488d (6.8), 5ab008650 (6.8), 05c7e3750 (tqtc/lts-6.5)
Description
PURL, CPE entries in qt_attribution.json files also need to contain a version identifier. This should be almost always the same as the version in "Version" entry, but copy/paste errors can happen, see e.g. https://codereview.qt-project.org/c/qt/qtbase/+/609805/3/src/3rdparty/sqlite/qt_attribution.json
Should we allow a placeholder in this case?
Attachments
Gerrit Reviews
For Gerrit Dashboard: QTBUG-132181 | ||||||
---|---|---|---|---|---|---|
# | Subject | Branch | Project | Status | CR | V |
614833,12 | CMake: Replace placeholders in CPE and PURL strings in SBOMs | dev | qt/qtbase | Status: MERGED | +2 | 0 |
614834,13 | CMake: Use the $<VERSION> placeholder in qt_attribution.json | dev | qt/qtbase | Status: MERGED | +2 | 0 |
616133,2 | CMake: Replace placeholders in CPE and PURL strings in SBOMs | 6.9 | qt/qtbase | Status: MERGED | +2 | 0 |
616154,2 | CMake: Use the $<VERSION> placeholder in qt_attribution.json | 6.9 | qt/qtbase | Status: MERGED | +2 | 0 |
616194,2 | CMake: Replace placeholders in CPE and PURL strings in SBOMs | 6.8 | qt/qtbase | Status: MERGED | +2 | 0 |
616195,3 | CMake: Use the $<VERSION> placeholder in qt_attribution.json | 6.8 | qt/qtbase | Status: MERGED | +2 | 0 |
619762,2 | CMake: Use the $<VERSION> placeholder in qt_attribution.json | tqtc/lts-6.5 | qt/tqtc-qtbase | Status: MERGED | +2 | 0 |