Skip to content

feat: upgrade CycloneDX lib 10.0.0#1503

Draft
jkowalleck wants to merge 4 commits intomasterfrom
feat/cyclonedx-lib-10.0.0
Draft

feat: upgrade CycloneDX lib 10.0.0#1503
jkowalleck wants to merge 4 commits intomasterfrom
feat/cyclonedx-lib-10.0.0

Conversation

@jkowalleck
Copy link
Member

@jkowalleck jkowalleck commented Feb 27, 2026

Description

  • Fixed
    • Qualified PackageURLs
  • Changed
    • Take care of PackageURL generation ourselves, now
      Previously, this was done at best-effort by a 3rd-party library.
  • Dependencies
    • Upgraded runtime-dependency @cyclonedx/cyclonedx-library@^10.0.0 now, was @^9.2.0
    • Added runtime-dependency packageurl-js@^2.0.1
    • Added runtime-dependency spdx-expression-parse@^3.0.1||^4.0.0

Resolves or fixes issue:

AI Tool Disclosure

  • My contribution does not include any AI-generated content
  • My contribution includes AI-generated content, as disclosed below:
    • AI Tools: [e.g. GitHub CoPilot, ChatGPT, JetBrains Junie etc.]
    • LLMs and versions: [e.g. GPT-4.1, Claude Haiku 4.5, Gemini 2.5 Pro etc.]
    • Prompts: [Summarize the key prompts or instructions given to the AI tools]

Affirmation

@jkowalleck jkowalleck requested a review from a team as a code owner February 27, 2026 09:25
@jkowalleck jkowalleck added enhancement New feature or request dependencies Pull requests that update a dependency file labels Feb 27, 2026
Signed-off-by: Jan Kowalleck <[email protected]>
Signed-off-by: Jan Kowalleck <[email protected]>
@jkowalleck jkowalleck marked this pull request as draft February 27, 2026 10:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant