Skip to content

Fix Spdx2to3Converter dropping packages with no relationships - #452

Merged
goneall merged 2 commits into
spdx:masterfrom
tiegz:fix/spdx2to3-orphan-packages
Oct 3, 2026
Merged

goneall merged 2 commits into
spdx:masterfrom
tiegz:fix/spdx2to3-orphan-packages

Conversation

@tiegz

@tiegz tiegz commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Spdx2to3Converter.convertAndStore(SpdxDocument) only discovered elements by walking documentDescribes and following Relationships. Any package, file, or snippet that existed in the source document but had no relationship to anything else and wasn't part of documentDescribes (i.e. an orphan) was never visited, so it was silently omitted from the converted SPDX 3 output.

Add a pass after the existing conversion that scans the source model store for any SpdxPackage/SpdxFile/SpdxSnippet not already converted and converts them, adding them as root elements of the resulting SpdxDocument.

…onships

Spdx2to3Converter.convertAndStore(SpdxDocument) only discovered elements
by walking documentDescribes and following Relationships. Any package,
file, or snippet that existed in the source document but had no
relationship to anything else and wasn't part of documentDescribes was
never visited, so it was silently omitted from the converted SPDX 3
output.

Add a pass after the existing conversion that scans the source model
store for any SpdxPackage/SpdxFile/SpdxSnippet not already converted
and converts them, adding them as root elements of the resulting
SpdxDocument.
@tiegz tiegz changed the title Fix Spdx2to3Converter dropping packages/etc with no relationships Fix Spdx2to3Converter dropping packages with no relationships Sep 29, 2026

@goneall goneall left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @tiegz - Agree with the issue and the solution looks correct.

I would add the concrete license classes to the list of orphan element types.

There is a use case where a collection of licenses are stored in an SPDX v2 document - these may or may not be included in the root element. Adding these would properly covert those documents.

Comment thread src/main/java/org/spdx/library/conversion/Spdx2to3Converter.java
…elements

Extracted licensing info, listed licenses, and listed license exceptions
that exist in a source document's model store but are not reachable from
documentDescribes, a relationship, or any referenced license expression
were previously dropped from the SPDX 3 output, since they were never
added to the document's root elements.

- Add extracted licenses to the root elements list directly, since they
  are already unconditionally converted from the document's
  extractedLicenseInfos.
- Scan the source model store for listed licenses and listed license
  exceptions not already converted, converting and rooting any orphans
  found (searched without a document URI prefix since these are stored
  under the SPDX License List namespace).
@goneall
goneall merged commit da2f8a1 into spdx:master Oct 3, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants