github.com/nextlinux/gosbom@v0.81.1-0.20230627115839-1ff50c281391/gosbom/formats/spdxjson/test-fixtures/snapshot/TestSPDXRelationshipOrder.golden (about)

     1  {
     2   "spdxVersion": "SPDX-2.3",
     3   "dataLicense": "CC0-1.0",
     4   "SPDXID": "SPDXRef-DOCUMENT",
     5   "name": "user-image-input",
     6   "documentNamespace": "https://anchore.com/gosbom/image/user-image-input-2a1392ab-7eb5-4f2a-86f6-777aef3232e1",
     7   "creationInfo": {
     8    "licenseListVersion": "3.20",
     9    "creators": [
    10     "Organization: Nextlinux, Inc",
    11     "Tool: gosbom-v0.42.0-bogus"
    12    ],
    13    "created": "2023-06-05T18:49:14Z"
    14   },
    15   "packages": [
    16    {
    17     "name": "package-1",
    18     "SPDXID": "SPDXRef-Package-python-package-1-125840abc1c66dd7",
    19     "versionInfo": "1.0.1",
    20     "downloadLocation": "NOASSERTION",
    21     "filesAnalyzed": false,
    22     "sourceInfo": "acquired package info from installed python package manifest file: /somefile-1.txt",
    23     "licenseConcluded": "NOASSERTION",
    24     "licenseDeclared": "MIT",
    25     "copyrightText": "NOASSERTION",
    26     "externalRefs": [
    27      {
    28       "referenceCategory": "SECURITY",
    29       "referenceType": "cpe23Type",
    30       "referenceLocator": "cpe:2.3:*:some:package:1:*:*:*:*:*:*:*"
    31      },
    32      {
    33       "referenceCategory": "PACKAGE-MANAGER",
    34       "referenceType": "purl",
    35       "referenceLocator": "a-purl-1"
    36      }
    37     ]
    38    },
    39    {
    40     "name": "package-2",
    41     "SPDXID": "SPDXRef-Package-deb-package-2-958443e2d9304af4",
    42     "versionInfo": "2.0.1",
    43     "downloadLocation": "NOASSERTION",
    44     "filesAnalyzed": false,
    45     "sourceInfo": "acquired package info from DPKG DB: /somefile-2.txt",
    46     "licenseConcluded": "NOASSERTION",
    47     "licenseDeclared": "NOASSERTION",
    48     "copyrightText": "NOASSERTION",
    49     "externalRefs": [
    50      {
    51       "referenceCategory": "SECURITY",
    52       "referenceType": "cpe23Type",
    53       "referenceLocator": "cpe:2.3:*:some:package:2:*:*:*:*:*:*:*"
    54      },
    55      {
    56       "referenceCategory": "PACKAGE-MANAGER",
    57       "referenceType": "purl",
    58       "referenceLocator": "pkg:deb/debian/package-2@2.0.1"
    59      }
    60     ]
    61    }
    62   ],
    63   "files": [
    64    {
    65     "fileName": "/a1/f6",
    66     "SPDXID": "SPDXRef-File-a1-f6-9c2f7510199b17f6",
    67     "fileTypes": [
    68      "OTHER"
    69     ],
    70     "checksums": [
    71      {
    72       "algorithm": "SHA1",
    73       "checksumValue": "0000000000000000000000000000000000000000"
    74      }
    75     ],
    76     "licenseConcluded": "NOASSERTION",
    77     "copyrightText": ""
    78    },
    79    {
    80     "fileName": "/d1/f3",
    81     "SPDXID": "SPDXRef-File-d1-f3-c6f5b29dca12661f",
    82     "fileTypes": [
    83      "OTHER"
    84     ],
    85     "checksums": [
    86      {
    87       "algorithm": "SHA1",
    88       "checksumValue": "0000000000000000000000000000000000000000"
    89      }
    90     ],
    91     "licenseConcluded": "NOASSERTION",
    92     "copyrightText": ""
    93    },
    94    {
    95     "fileName": "/d2/f4",
    96     "SPDXID": "SPDXRef-File-d2-f4-c641caa71518099f",
    97     "fileTypes": [
    98      "OTHER"
    99     ],
   100     "checksums": [
   101      {
   102       "algorithm": "SHA1",
   103       "checksumValue": "0000000000000000000000000000000000000000"
   104      }
   105     ],
   106     "licenseConcluded": "NOASSERTION",
   107     "copyrightText": ""
   108    },
   109    {
   110     "fileName": "/f1",
   111     "SPDXID": "SPDXRef-File-f1-5265a4dde3edbf7c",
   112     "fileTypes": [
   113      "OTHER"
   114     ],
   115     "checksums": [
   116      {
   117       "algorithm": "SHA1",
   118       "checksumValue": "0000000000000000000000000000000000000000"
   119      }
   120     ],
   121     "licenseConcluded": "NOASSERTION",
   122     "copyrightText": ""
   123    },
   124    {
   125     "fileName": "/f2",
   126     "SPDXID": "SPDXRef-File-f2-f9e49132a4b96ccd",
   127     "fileTypes": [
   128      "OTHER"
   129     ],
   130     "checksums": [
   131      {
   132       "algorithm": "SHA1",
   133       "checksumValue": "0000000000000000000000000000000000000000"
   134      }
   135     ],
   136     "licenseConcluded": "NOASSERTION",
   137     "copyrightText": ""
   138    },
   139    {
   140     "fileName": "/z1/f5",
   141     "SPDXID": "SPDXRef-File-z1-f5-839d99ee67d9d174",
   142     "fileTypes": [
   143      "OTHER"
   144     ],
   145     "checksums": [
   146      {
   147       "algorithm": "SHA1",
   148       "checksumValue": "0000000000000000000000000000000000000000"
   149      }
   150     ],
   151     "licenseConcluded": "NOASSERTION",
   152     "copyrightText": ""
   153    }
   154   ],
   155   "relationships": [
   156    {
   157     "spdxElementId": "SPDXRef-Package-python-package-1-125840abc1c66dd7",
   158     "relatedSpdxElement": "SPDXRef-File-f1-5265a4dde3edbf7c",
   159     "relationshipType": "CONTAINS"
   160    },
   161    {
   162     "spdxElementId": "SPDXRef-Package-python-package-1-125840abc1c66dd7",
   163     "relatedSpdxElement": "SPDXRef-File-z1-f5-839d99ee67d9d174",
   164     "relationshipType": "CONTAINS"
   165    },
   166    {
   167     "spdxElementId": "SPDXRef-Package-python-package-1-125840abc1c66dd7",
   168     "relatedSpdxElement": "SPDXRef-File-a1-f6-9c2f7510199b17f6",
   169     "relationshipType": "CONTAINS"
   170    },
   171    {
   172     "spdxElementId": "SPDXRef-Package-python-package-1-125840abc1c66dd7",
   173     "relatedSpdxElement": "SPDXRef-File-d2-f4-c641caa71518099f",
   174     "relationshipType": "CONTAINS"
   175    },
   176    {
   177     "spdxElementId": "SPDXRef-Package-python-package-1-125840abc1c66dd7",
   178     "relatedSpdxElement": "SPDXRef-File-d1-f3-c6f5b29dca12661f",
   179     "relationshipType": "CONTAINS"
   180    },
   181    {
   182     "spdxElementId": "SPDXRef-Package-python-package-1-125840abc1c66dd7",
   183     "relatedSpdxElement": "SPDXRef-File-f2-f9e49132a4b96ccd",
   184     "relationshipType": "CONTAINS"
   185    },
   186    {
   187     "spdxElementId": "SPDXRef-DOCUMENT",
   188     "relatedSpdxElement": "SPDXRef-DOCUMENT",
   189     "relationshipType": "DESCRIBES"
   190    }
   191   ]
   192  }