diff --git a/.gitignore b/.gitignore index 5f18d50..2e40de1 100644 --- a/.gitignore +++ b/.gitignore @@ -18,3 +18,7 @@ buildNumber.properties # IntelliJ IDE .idea +*.iml + +# macOS +.DS_Store diff --git a/README.md b/README.md index 86186c7..ab4d753 100644 --- a/README.md +++ b/README.md @@ -25,10 +25,14 @@ This utility supports versions 2.0, 2.1, 2.2, 2.3 and 3.0.1 of the SPDX specific [![Maintainability Rating](https://sonarcloud.io/api/project_badges/measure?project=tools-java&metric=sqale_rating)](https://sonarcloud.io/dashboard?id=tools-java) [![Technical Debt](https://sonarcloud.io/api/project_badges/measure?project=tools-java&metric=sqale_index)](https://sonarcloud.io/dashboard?id=tools-java) -## Getting Starting +## Getting Started The SPDX Tools binaries can be downloaded from the [releases page](https://github.com/spdx/tools-java/releases) under the respective release. The package is also available in [Maven Central](https://central.sonatype.com/artifact/org.spdx/tools-java) (organization `org.spdx`, artifact `tools-java`). +Running the tools requires a Java Runtime Environment (JRE) +or Java Development Kit (JDK) version 11 or later. +Building from source requires JDK 11 or later and Apache Maven. + See the Syntax section below for the commands available. If you are a developer, there are examples in the [examples folder](examples/org/spdx/examples). @@ -113,6 +117,46 @@ The following tool can be used to generate an SPDX verification code from a dire java -jar tools-java-2.0.7-jar-with-dependencies.jar GenerateVerificationCode sourceDirectory [ignoredFilesRegex] +## License matching + +The following tool lists the SPDX License List identifiers whose text matches +a license text file, using the +[SPDX License List matching guidelines][matching]: + +* MatchingStandardLicenses licenseTextFile + +Sample usage: + + java -jar tools-java-2.0.7-jar-with-dependencies.jar MatchingStandardLicenses LICENSE + +Prints the matching license IDs, or `No standard licenses matched.` + +[matching]: https://spdx.github.io/spdx-spec/v3.0/annexes/license-matching-guidelines-and-templates/ + +## Version + +The following command prints the version of the tool, +the SPDX specification and the SPDX License List: + +* Version + +Sample usage: + + java -jar tools-java-2.0.7-jar-with-dependencies.jar Version + +## Exit codes + +The tools return the following process exit codes: + +| Code | Meaning | +| ---- | ------- | +| 0 | Success - e.g. the document is valid, or the conversion completed | +| 1 | Failure - e.g. the document is invalid or could not be read, or the operation failed | +| 2 | Incorrect usage - missing, invalid or unrecognized arguments | + +For `MatchingStandardLicenses`, exit code 0 means the comparison completed, +whether or not a license matched. + ## SPDX Validation Tool The SPDX Workgroup provides an online interface to validate, compare, and convert SPDX documents in addition to the command line options above. @@ -121,8 +165,6 @@ The [SPDX Online Tools](https://tools.spdx.org/) is an all-in-one portal to uplo ## License -A complete SPDX file is available including dependencies is available in the bintray and Maven repos. - SPDX-License-Identifier: Apache-2.0 PackageLicenseDeclared: Apache-2.0 diff --git a/RELEASE-CHECKLIST.md b/RELEASE-CHECKLIST.md index 32529c2..4934b2f 100644 --- a/RELEASE-CHECKLIST.md +++ b/RELEASE-CHECKLIST.md @@ -1,12 +1,11 @@ # Release Checklist for the SPDX Java Tools -- [ ] Check for any warnings from the compiler and findbugs +- [ ] Check for any warnings from the compiler and SpotBugs `mvn spotbugs:check` - [ ] Run unit tests for all packages that depend on the application - [ ] Run dependency check to find any potential vulnerabilities `mvn dependency-check:check` -- [ ] Update the README.md file with the new version of the jar file +- [ ] Update README.md to refer to the new version of the jar file, in the Syntax section and other sections - [ ] Run `mvn release:prepare` - you will be prompted for the release - typically take the defaults - [ ] Run `mvn release:perform` - [ ] Release artifacts to Maven Central - [ ] Create a Git release including release notes - [ ] Zip up the files from the Maven archive and add them to the release -- [ ] Update README to refer to the new release in the Syntax section diff --git a/tools-java.iml b/tools-java.iml deleted file mode 100644 index ae72666..0000000 --- a/tools-java.iml +++ /dev/null @@ -1,8 +0,0 @@ - - - - - - - - \ No newline at end of file