From 503b9ec6ca12fe4975f0dd45bb044bbdfe883b5b Mon Sep 17 00:00:00 2001 From: Arthit Suriyawongkul Date: Fri, 18 Sep 2026 19:43:59 +0100 Subject: [PATCH 1/4] Update README and RELEASE-CHECKLIST Signed-off-by: Arthit Suriyawongkul --- .gitignore | 4 ++++ README.md | 40 ++++++++++++++++++++++++++++++++++++++-- RELEASE-CHECKLIST.md | 5 ++--- 3 files changed, 44 insertions(+), 5 deletions(-) diff --git a/.gitignore b/.gitignore index 5f18d50..2e40de1 100644 --- a/.gitignore +++ b/.gitignore @@ -18,3 +18,7 @@ buildNumber.properties # IntelliJ IDE .idea +*.iml + +# macOS +.DS_Store diff --git a/README.md b/README.md index 86186c7..9a19d8f 100644 --- a/README.md +++ b/README.md @@ -25,10 +25,12 @@ This utility supports versions 2.0, 2.1, 2.2, 2.3 and 3.0.1 of the SPDX specific [![Maintainability Rating](https://sonarcloud.io/api/project_badges/measure?project=tools-java&metric=sqale_rating)](https://sonarcloud.io/dashboard?id=tools-java) [![Technical Debt](https://sonarcloud.io/api/project_badges/measure?project=tools-java&metric=sqale_index)](https://sonarcloud.io/dashboard?id=tools-java) -## Getting Starting +## Getting Started The SPDX Tools binaries can be downloaded from the [releases page](https://github.com/spdx/tools-java/releases) under the respective release. The package is also available in [Maven Central](https://central.sonatype.com/artifact/org.spdx/tools-java) (organization `org.spdx`, artifact `tools-java`). +Running the tools requires a Java Runtime Environment (JRE) or Java Development Kit (JDK) version 11 or later. Building from source requires JDK 11 or later and Apache Maven. + See the Syntax section below for the commands available. If you are a developer, there are examples in the [examples folder](examples/org/spdx/examples). @@ -113,6 +115,40 @@ The following tool can be used to generate an SPDX verification code from a dire java -jar tools-java-2.0.7-jar-with-dependencies.jar GenerateVerificationCode sourceDirectory [ignoredFilesRegex] +## License matching + +The following tool lists the SPDX License List identifiers whose text matches a license text file, using the [SPDX matching guidelines](https://spdx.org/licenses/matching-guidelines.html): + +* MatchingStandardLicenses licenseTextFile + +Sample usage: + + java -jar tools-java-2.0.7-jar-with-dependencies.jar MatchingStandardLicenses LICENSE + +Prints the matching license ids, or `No standard licenses matched.` + +## Version + +The following command prints the version of the tool, the SPDX specification and the SPDX License List: + +* Version + +Sample usage: + + java -jar tools-java-2.0.7-jar-with-dependencies.jar Version + +## Exit codes + +The tools return the following process exit codes, which can be used in scripts and CI: + +| Code | Meaning | +| ---- | ------- | +| 0 | Success - e.g. the document is valid, or the conversion completed | +| 1 | Failure - e.g. the document is invalid or could not be read, or the operation failed | +| 2 | Incorrect usage - missing, invalid or unrecognized arguments | + +For `MatchingStandardLicenses`, exit code 0 means the comparison completed, whether or not a license matched. + ## SPDX Validation Tool The SPDX Workgroup provides an online interface to validate, compare, and convert SPDX documents in addition to the command line options above. @@ -121,7 +157,7 @@ The [SPDX Online Tools](https://tools.spdx.org/) is an all-in-one portal to uplo ## License -A complete SPDX file is available including dependencies is available in the bintray and Maven repos. +A complete SPDX file, including dependencies, is available in the [Maven Central](https://central.sonatype.com/artifact/org.spdx/tools-java) repository. SPDX-License-Identifier: Apache-2.0 PackageLicenseDeclared: Apache-2.0 diff --git a/RELEASE-CHECKLIST.md b/RELEASE-CHECKLIST.md index 32529c2..4934b2f 100644 --- a/RELEASE-CHECKLIST.md +++ b/RELEASE-CHECKLIST.md @@ -1,12 +1,11 @@ # Release Checklist for the SPDX Java Tools -- [ ] Check for any warnings from the compiler and findbugs +- [ ] Check for any warnings from the compiler and SpotBugs `mvn spotbugs:check` - [ ] Run unit tests for all packages that depend on the application - [ ] Run dependency check to find any potential vulnerabilities `mvn dependency-check:check` -- [ ] Update the README.md file with the new version of the jar file +- [ ] Update README.md to refer to the new version of the jar file, in the Syntax section and other sections - [ ] Run `mvn release:prepare` - you will be prompted for the release - typically take the defaults - [ ] Run `mvn release:perform` - [ ] Release artifacts to Maven Central - [ ] Create a Git release including release notes - [ ] Zip up the files from the Maven archive and add them to the release -- [ ] Update README to refer to the new release in the Syntax section From 8cb8f8f53cae4e0d911b5507c143bc59918cb338 Mon Sep 17 00:00:00 2001 From: Arthit Suriyawongkul Date: Fri, 18 Sep 2026 19:48:12 +0100 Subject: [PATCH 2/4] Delete tools-java.iml Signed-off-by: Arthit Suriyawongkul --- tools-java.iml | 8 -------- 1 file changed, 8 deletions(-) delete mode 100644 tools-java.iml diff --git a/tools-java.iml b/tools-java.iml deleted file mode 100644 index ae72666..0000000 --- a/tools-java.iml +++ /dev/null @@ -1,8 +0,0 @@ - - - - - - - - \ No newline at end of file From cb5040d3adcae6260dff78d371d047e3f82d20fa Mon Sep 17 00:00:00 2001 From: Arthit Suriyawongkul Date: Fri, 18 Sep 2026 19:57:05 +0100 Subject: [PATCH 3/4] Update matching guide URL Signed-off-by: Arthit Suriyawongkul --- README.md | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 9a19d8f..bca78b6 100644 --- a/README.md +++ b/README.md @@ -117,7 +117,9 @@ The following tool can be used to generate an SPDX verification code from a dire ## License matching -The following tool lists the SPDX License List identifiers whose text matches a license text file, using the [SPDX matching guidelines](https://spdx.org/licenses/matching-guidelines.html): +The following tool lists the SPDX License List identifiers whose text matches +a license text file, using the +[SPDX License List matching guidelines][matching]: * MatchingStandardLicenses licenseTextFile @@ -125,11 +127,14 @@ Sample usage: java -jar tools-java-2.0.7-jar-with-dependencies.jar MatchingStandardLicenses LICENSE -Prints the matching license ids, or `No standard licenses matched.` +Prints the matching license IDs, or `No standard licenses matched.` + +[matching]: https://spdx.github.io/spdx-spec/v3.0/annexes/license-matching-guidelines-and-templates/ ## Version -The following command prints the version of the tool, the SPDX specification and the SPDX License List: +The following command prints the version of the tool, +the SPDX specification and the SPDX License List: * Version @@ -139,7 +144,7 @@ Sample usage: ## Exit codes -The tools return the following process exit codes, which can be used in scripts and CI: +The tools return the following process exit codes: | Code | Meaning | | ---- | ------- | @@ -147,7 +152,8 @@ The tools return the following process exit codes, which can be used in scripts | 1 | Failure - e.g. the document is invalid or could not be read, or the operation failed | | 2 | Incorrect usage - missing, invalid or unrecognized arguments | -For `MatchingStandardLicenses`, exit code 0 means the comparison completed, whether or not a license matched. +For `MatchingStandardLicenses`, exit code 0 means the comparison completed, +whether or not a license matched. ## SPDX Validation Tool From 67d0dedafc925b39d21d022ed22d8954ba1ddaeb Mon Sep 17 00:00:00 2001 From: Arthit Suriyawongkul Date: Fri, 18 Sep 2026 20:03:01 +0100 Subject: [PATCH 4/4] Remove irrelevant Maven mention in License section Signed-off-by: Arthit Suriyawongkul --- README.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index bca78b6..ab4d753 100644 --- a/README.md +++ b/README.md @@ -29,7 +29,9 @@ This utility supports versions 2.0, 2.1, 2.2, 2.3 and 3.0.1 of the SPDX specific The SPDX Tools binaries can be downloaded from the [releases page](https://github.com/spdx/tools-java/releases) under the respective release. The package is also available in [Maven Central](https://central.sonatype.com/artifact/org.spdx/tools-java) (organization `org.spdx`, artifact `tools-java`). -Running the tools requires a Java Runtime Environment (JRE) or Java Development Kit (JDK) version 11 or later. Building from source requires JDK 11 or later and Apache Maven. +Running the tools requires a Java Runtime Environment (JRE) +or Java Development Kit (JDK) version 11 or later. +Building from source requires JDK 11 or later and Apache Maven. See the Syntax section below for the commands available. @@ -163,8 +165,6 @@ The [SPDX Online Tools](https://tools.spdx.org/) is an all-in-one portal to uplo ## License -A complete SPDX file, including dependencies, is available in the [Maven Central](https://central.sonatype.com/artifact/org.spdx/tools-java) repository. - SPDX-License-Identifier: Apache-2.0 PackageLicenseDeclared: Apache-2.0