Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -18,3 +18,7 @@ buildNumber.properties

# IntelliJ IDE
.idea
*.iml

# macOS
.DS_Store
48 changes: 45 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,14 @@ This utility supports versions 2.0, 2.1, 2.2, 2.3 and 3.0.1 of the SPDX specific
[![Maintainability Rating](https://sonarcloud.io/api/project_badges/measure?project=tools-java&metric=sqale_rating)](https://sonarcloud.io/dashboard?id=tools-java)
[![Technical Debt](https://sonarcloud.io/api/project_badges/measure?project=tools-java&metric=sqale_index)](https://sonarcloud.io/dashboard?id=tools-java)

## Getting Starting
## Getting Started

The SPDX Tools binaries can be downloaded from the [releases page](https://github.com/spdx/tools-java/releases) under the respective release. The package is also available in [Maven Central](https://central.sonatype.com/artifact/org.spdx/tools-java) (organization `org.spdx`, artifact `tools-java`).

Running the tools requires a Java Runtime Environment (JRE)
or Java Development Kit (JDK) version 11 or later.
Building from source requires JDK 11 or later and Apache Maven.

See the Syntax section below for the commands available.

If you are a developer, there are examples in the [examples folder](examples/org/spdx/examples).
Expand Down Expand Up @@ -113,6 +117,46 @@ The following tool can be used to generate an SPDX verification code from a dire

java -jar tools-java-2.0.7-jar-with-dependencies.jar GenerateVerificationCode sourceDirectory [ignoredFilesRegex]

## License matching

The following tool lists the SPDX License List identifiers whose text matches
a license text file, using the
[SPDX License List matching guidelines][matching]:

* MatchingStandardLicenses licenseTextFile

Sample usage:

java -jar tools-java-2.0.7-jar-with-dependencies.jar MatchingStandardLicenses LICENSE

Prints the matching license IDs, or `No standard licenses matched.`

[matching]: https://spdx.github.io/spdx-spec/v3.0/annexes/license-matching-guidelines-and-templates/

## Version

The following command prints the version of the tool,
the SPDX specification and the SPDX License List:

* Version

Sample usage:

java -jar tools-java-2.0.7-jar-with-dependencies.jar Version

## Exit codes

The tools return the following process exit codes:

| Code | Meaning |
| ---- | ------- |
| 0 | Success - e.g. the document is valid, or the conversion completed |
| 1 | Failure - e.g. the document is invalid or could not be read, or the operation failed |
| 2 | Incorrect usage - missing, invalid or unrecognized arguments |

For `MatchingStandardLicenses`, exit code 0 means the comparison completed,
whether or not a license matched.

## SPDX Validation Tool

The SPDX Workgroup provides an online interface to validate, compare, and convert SPDX documents in addition to the command line options above.
Expand All @@ -121,8 +165,6 @@ The [SPDX Online Tools](https://tools.spdx.org/) is an all-in-one portal to uplo

## License

A complete SPDX file is available including dependencies is available in the bintray and Maven repos.

SPDX-License-Identifier: Apache-2.0
PackageLicenseDeclared: Apache-2.0

Expand Down
5 changes: 2 additions & 3 deletions RELEASE-CHECKLIST.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,11 @@
# Release Checklist for the SPDX Java Tools

- [ ] Check for any warnings from the compiler and findbugs
- [ ] Check for any warnings from the compiler and SpotBugs `mvn spotbugs:check`
- [ ] Run unit tests for all packages that depend on the application
- [ ] Run dependency check to find any potential vulnerabilities `mvn dependency-check:check`
- [ ] Update the README.md file with the new version of the jar file
- [ ] Update README.md to refer to the new version of the jar file, in the Syntax section and other sections
- [ ] Run `mvn release:prepare` - you will be prompted for the release - typically take the defaults
- [ ] Run `mvn release:perform`
- [ ] Release artifacts to Maven Central
- [ ] Create a Git release including release notes
- [ ] Zip up the files from the Maven archive and add them to the release
- [ ] Update README to refer to the new release in the Syntax section
8 changes: 0 additions & 8 deletions tools-java.iml

This file was deleted.

Loading