The SPDX libraries were originally added to this repo to make it easier to initially iterate on the implementation in step with the CDX libraries in this repo.
I'm proposing to migrate the SPDX and SPDX Interop libraries to their own individual repos.
There's a couple of potential benefits including:
- reduced notification fatigue for maintainers who are focused on the CDX libraries and not the SPDX ones
- finer grained scope for potential future maintainers to be onboarded
- the opportunity to more easily open up SPDX libraries to external collaborators from the SPDX community
I can't think of any real downsides except library versions will start drifting between the core CDX libraries and the SPDX ones.
The SPDX libraries were originally added to this repo to make it easier to initially iterate on the implementation in step with the CDX libraries in this repo.
I'm proposing to migrate the SPDX and SPDX Interop libraries to their own individual repos.
There's a couple of potential benefits including:
I can't think of any real downsides except library versions will start drifting between the core CDX libraries and the SPDX ones.