Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 31, 2023

Bumps spdx-tools from 0.7.1 to 0.8.0.

Release notes

Sourced from spdx-tools's releases.

v0.8.0

What's Changed

... (truncated)

Changelog

Sourced from spdx-tools's changelog.

v0.8.0 (2023-07-25)

New features and changes

  • major refactoring of the library
    • new and improved data model
    • type hints and type checks have been added to the model classes
    • license expressions and SPDX license list are now handled by the license-expression package
    • to update your existing code, refer to the migration guide
  • experimental support for the upcoming SPDX v3 specification (note, however, that support is neither complete nor stable at this point, as the spec is still evolving)
  • full validation of SPDX documents against the v2.2 and v2.3 specification
  • support for SPDX's RDF format with all v2.3 features
  • unified pysdpxtools CLI tool replaces separate pyspdxtools_parser and pyspdxtools_convertor
  • online API documentation
  • replaced CircleCI with GitHub Actions

Contributors

This release was made possible by the following contributors. Thank you very much!

Commits
  • 69eea91 update README and CHANGELOG for the upcoming release
  • ef31285 add script to publish from tag
  • 8ef0cef set validate=True as default value in the rdf writer to be consistent with th...
  • 2402596 make "Package CONTAINS Package" valid even when files_analyzed == False
  • 17767bd Merge pull request #729 from armintaenzertng/remove_CircleCI
  • 4dad0e1 remove unused CircleCI workflow and directory
  • 9b8183e [issue-722] change return type of calculate_package_verification_code() to Pa...
  • c62cead Merge pull request #727 from fholger/profile_identifier
  • 8e8a246 SPDX3: rename ProfileIdentifier to ProfileIdentifierType to be consistent wit...
  • cba5db5 Merge pull request #723 from armintaenzertng/addVerificationCodeCalculator
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [spdx-tools](https://github.com/spdx/tools-python) from 0.7.1 to 0.8.0.
- [Release notes](https://github.com/spdx/tools-python/releases)
- [Changelog](https://github.com/spdx/tools-python/blob/main/CHANGELOG.md)
- [Commits](spdx/tools-python@v0.7.1...v0.8.0)

---
updated-dependencies:
- dependency-name: spdx-tools
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner July 31, 2023 13:55
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Jul 31, 2023
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Aug 28, 2023

Superseded by #65.

@dependabot dependabot bot closed this Aug 28, 2023
@dependabot dependabot bot deleted the dependabot/pip/spdx-tools-0.8.0 branch August 28, 2023 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant