Add licenses and description fields when using --rpm-package option #40
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This patch allows us to add licenses and description information when using the --rpm-package option. For SPDX, a summary is also added. Note that the licenses information includes a provisional implementation, so it may be modified in the future.
However, applying this patch may cause it to stop working on distributions other than AlmaLinux and other EL-based distributions. The rpm module (rpm-shim) used to analyze information from RPM packages is a module that uses the RPM Python bindings provided by the installed python3-rpm package. python3-rpm package is installed on almost all AlmaLinux systems except for some like containers because it is a transitive dependency of the dnf package, which is installed by default in a minimal installation. However, for example on Ubuntu, there is a package with the same name python3-rpm, but alma-sbom did not work properly if I installed it.
This patch needs to merge #39