ntia_conformance_checker.adapters package¶
Submodules¶
ntia_conformance_checker.adapters.adapter_interface module¶
Blueprint interface for SBOM adapters.
- class ntia_conformance_checker.adapters.adapter_interface.SbomAdapter[source]¶
Bases:
ABCAbstract base class defining the standard interface for all SBOM adapters.
- abstractmethod check_dependency_relationships() bool[source]¶
Check if the SBOM document declares dependency information.
- abstractmethod get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing unique identifiers (SPDX IDs).
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_doc_spec_version() str | None[source]¶
Retrieve the document’s specification version.
- abstractmethod get_sbom_types(conformance_messages: list[ValidationMessage]) list[str][source]¶
Get SBOM types from the rootElement of the SpdxDocument.
CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024
- ntia_conformance_checker.adapters.adapter_interface.is_blank_string(value: object, noassertion: bool = False) bool[source]¶
Check whether a value is a blank string.
Blank means whitespace-only, or
NOASSERTION(any case) whennoassertionis set. Usenoassertiononly for fields where the SPDX specification defines it (supplier, license, copyright).NONEis a statement, so it is not blank.- Parameters:
value – The value to check.
noassertion – Whether
NOASSERTIONcounts as blank.
- Returns:
True if
valueis a blank string.- Return type:
bool
ntia_conformance_checker.adapters.null_adapter module¶
Adapter for when parsing fails.
- class ntia_conformance_checker.adapters.null_adapter.NullAdapter[source]¶
Bases:
SbomAdapterAdapter returning defaults, used when parsing fails.
- check_dependency_relationships() bool[source]¶
Check if the SBOM document declares dependency information.
- get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing unique identifiers (SPDX IDs).
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_sbom_types(conformance_messages: list[ValidationMessage]) list[str][source]¶
Get SBOM types from the rootElement of the SpdxDocument.
CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024
ntia_conformance_checker.adapters.spdx2_adapter module¶
SPDX 2.x specific data extraction adapter.
- class ntia_conformance_checker.adapters.spdx2_adapter.Spdx2Adapter(doc: Document)[source]¶
Bases:
SbomAdapterAdapter for extracting data from SPDX 2.x documents.
- get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing unique identifiers (SPDX IDs).
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_sbom_types(conformance_messages: list[ValidationMessage]) list[str][source]¶
Get SBOM types from the rootElement of the SpdxDocument.
CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024
ntia_conformance_checker.adapters.spdx3_adapter module¶
SPDX 3.x specific data extraction adapter.
- class ntia_conformance_checker.adapters.spdx3_adapter.Spdx3Adapter(object_set: SHACLObjectSet, spdx3_doc: SpdxDocument | None)[source]¶
Bases:
SbomAdapterAdapter for extracting data from SPDX 3.x documents.
- check_dependency_relationships() bool[source]¶
In SPDX 3, this checks package-level dependency relationships.
- get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Note that SPDX 3 requires identifiers for all elements, so this should not happen in a valid SPDX 3 document. The spdx-python-model JSON deserializer will raise a ValueError if any element is missing an identifier.
- get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- ntia_conformance_checker.adapters.spdx3_adapter.is_blank_license_expression(obj: object) bool[source]¶
Check whether an object is a license expression without license information.
- Parameters:
obj – The object to check, e.g. a relationship target.
- Returns:
True if
objis asimplelicensing_LicenseExpressionwhose text is blank,NOASSERTION, or names theNoAssertionLicenseindividual.- Return type:
bool
Module contents¶
Adapter package for handling multiple SBOM specifications.
- class ntia_conformance_checker.adapters.NullAdapter[source]¶
Bases:
SbomAdapterAdapter returning defaults, used when parsing fails.
- check_dependency_relationships() bool[source]¶
Check if the SBOM document declares dependency information.
- get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing unique identifiers (SPDX IDs).
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_sbom_types(conformance_messages: list[ValidationMessage]) list[str][source]¶
Get SBOM types from the rootElement of the SpdxDocument.
CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024
- class ntia_conformance_checker.adapters.SbomAdapter[source]¶
Bases:
ABCAbstract base class defining the standard interface for all SBOM adapters.
- abstractmethod check_dependency_relationships() bool[source]¶
Check if the SBOM document declares dependency information.
- abstractmethod get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing unique identifiers (SPDX IDs).
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- abstractmethod get_doc_spec_version() str | None[source]¶
Retrieve the document’s specification version.
- abstractmethod get_sbom_types(conformance_messages: list[ValidationMessage]) list[str][source]¶
Get SBOM types from the rootElement of the SpdxDocument.
CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024
- class ntia_conformance_checker.adapters.Spdx2Adapter(doc: Document)[source]¶
Bases:
SbomAdapterAdapter for extracting data from SPDX 2.x documents.
- get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing unique identifiers (SPDX IDs).
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_sbom_types(conformance_messages: list[ValidationMessage]) list[str][source]¶
Get SBOM types from the rootElement of the SpdxDocument.
CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024
- class ntia_conformance_checker.adapters.Spdx3Adapter(object_set: SHACLObjectSet, spdx3_doc: SpdxDocument | None)[source]¶
Bases:
SbomAdapterAdapter for extracting data from SPDX 3.x documents.
- check_dependency_relationships() bool[source]¶
In SPDX 3, this checks package-level dependency relationships.
- get_components_without_concluded_licenses(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a concluded license.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_copyright_texts(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a copyright text.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_identifiers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Note that SPDX 3 requires identifiers for all elements, so this should not happen in a valid SPDX 3 document. The spdx-python-model JSON deserializer will raise a ValueError if any element is missing an identifier.
- get_components_without_names(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing a name.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_suppliers(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing supplier information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]
- get_components_without_versions(reachable_ids: set[str]) list[tuple[str, str]][source]¶
Retrieve components missing version information.
- Returns:
A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.
- Return type:
list[tuple[str, str]]