Skip to main content

Component

Struct Component 

Source
pub struct Component {
Show 26 fields pub canonical_id: CanonicalId, pub identifiers: ComponentIdentifiers, pub name: String, pub version: Option<String>, pub semver: Option<Version>, pub component_type: ComponentType, pub ecosystem: Option<Ecosystem>, pub licenses: LicenseInfo, pub supplier: Option<Organization>, pub hashes: Vec<Hash>, pub external_refs: Vec<ExternalReference>, pub vulnerabilities: Vec<VulnerabilityRef>, pub vex_status: Option<VexStatus>, pub content_hash: u64, pub extensions: ComponentExtensions, pub description: Option<String>, pub copyright: Option<String>, pub author: Option<String>, pub group: Option<String>, pub is_external: bool, pub version_range: Option<String>, pub staleness: Option<StalenessInfo>, pub eol: Option<EolInfo>, pub ml_model: Option<MlModelInfo>, pub dataset: Option<DatasetInfo>, pub crypto_properties: Option<CryptoProperties>,
}
Expand description

Component in the normalized SBOM

Fields§

§canonical_id: CanonicalId

Canonical identifier

§identifiers: ComponentIdentifiers

Various identifiers (PURL, CPE, etc.)

§name: String

Component name

§version: Option<String>

Version string

§semver: Option<Version>

Parsed semantic version (if valid)

§component_type: ComponentType

Component type

§ecosystem: Option<Ecosystem>

Package ecosystem

§licenses: LicenseInfo

License information

§supplier: Option<Organization>

Supplier/vendor information

§hashes: Vec<Hash>

Cryptographic hashes

§external_refs: Vec<ExternalReference>

External references

§vulnerabilities: Vec<VulnerabilityRef>

Known vulnerabilities

§vex_status: Option<VexStatus>

VEX status

§content_hash: u64

Content hash for quick comparison

§extensions: ComponentExtensions

Format-specific extensions

§description: Option<String>

Description

§copyright: Option<String>

Copyright text

§author: Option<String>

Author information

§group: Option<String>

Group/namespace (e.g., Maven groupId)

§is_external: bool

Whether this component is external (expected from environment, not bundled)

§version_range: Option<String>

Package URL Version Range (vers) syntax, only valid when is_external is true

§staleness: Option<StalenessInfo>

Staleness information (populated by enrichment)

§eol: Option<EolInfo>

End-of-life information (populated by enrichment)

§ml_model: Option<MlModelInfo>

ML model metadata (populated for MachineLearningModel components)

§dataset: Option<DatasetInfo>

Dataset metadata (populated for Data components)

§crypto_properties: Option<CryptoProperties>

Cryptographic properties (CycloneDX 1.6+ cryptoProperties)

Implementations§

Source§

impl Component

Source

pub fn new(name: String, format_id: String) -> Self

Create a new component with minimal required fields

Source

pub fn with_purl(self, purl: String) -> Self

Set the PURL and update canonical ID

Source

pub fn set_purl(&mut self, purl: String)

Set the PURL in place, refreshing the canonical ID and deriving the ecosystem from the PURL type. Mirrors Self::with_purl for callers holding a &mut Component (e.g. enrichment that synthesizes a PURL).

Source

pub fn with_version(self, version: String) -> Self

Set the version and try to parse as semver

Source

pub fn with_swhid(self, swhid: String) -> Self

Add a Software Heritage persistent identifier (SWHID) from a string.

Invalid SWHIDs are silently dropped (matches the parser-tolerant behaviour of CanonicalId::from_swhid). Use with_swhid_object when you already have a SwhidObject in hand.

Recognised by CRA prEN 40000-1-3 [PRE-7-RQ-07] as one of the three named identifier types (alongside PURL and CPE). Multiple SWHIDs can be attached to a single component (e.g., a dir SWHID for the unpacked tree plus cnt SWHIDs for individual files).

Source

pub fn with_swhid_object(self, swhid: SwhidObject) -> Self

Add a structured SwhidObject SWHID.

Source

pub fn with_ml_model(self, ml_model: MlModelInfo) -> Self

Attach ML model metadata (CycloneDX modelCard)

Source

pub fn with_dataset(self, dataset: DatasetInfo) -> Self

Attach dataset metadata (CycloneDX ML BOM dataset component)

Source

pub fn calculate_content_hash(&mut self)

Calculate and update content hash.

Every field is tagged and length-prefixed (see extend_tagged) so a value moving between fields always changes the hash. Coverage matters: the diff’s modified-component gate and the incremental cache key both trust this hash, so any semantic field left out produces silently empty or stale diffs (vulnerability severity and VEX status were previously invisible here).

Source

pub fn is_oss(&self) -> bool

Check if this is an OSS (open source) component

Source

pub fn display_name(&self) -> String

Get display name with version

Trait Implementations§

Source§

impl Clone for Component

Source§

fn clone(&self) -> Component

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Component

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for Component

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl From<&Component> for ComponentRef

Source§

fn from(component: &Component) -> Self

Converts to this type from the input type.
Source§

impl Serialize for Component

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more