Skip to content

Commit d1d2ccf

Browse files
committed
docs(guide): 更新文档中的 SPDX 相关信息
- 修正代码块中的 Bun 标签大小写 - 移除 oh_modules 周围的反引号以改善显示 - 移除 Apache-2.0 OR MIT 周围的反引号以改善显示 - 在首页添加 SPDX 介绍信息框 - 在英文版介绍指南中添加 SPDX 说明 - 在中文版介绍指南中添加 SPDX 说明
1 parent 9560247 commit d1d2ccf

6 files changed

Lines changed: 28 additions & 4 deletions

File tree

‎guide/getting-started.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ pnpm add -D osslibraries-hvigor-plugin
7272
yarn add -D osslibraries-hvigor-plugin
7373
```
7474
75-
```sh [bun]
75+
```sh [Bun]
7676
bun add -D osslibraries-hvigor-plugin
7777
```
7878

‎guide/introduction.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,12 @@ OSSLibraries leaves the maintenance to the build: the plugin inspects the real d
2828
- Correct handling of SPDX expressions (`Apache-2.0 OR MIT`), misspellings, and multiple versions of the same dependency.
2929
- Two options at runtime: prebuilt UI pages, or the core data API with a custom UI.
3030

31+
::: info What is SPDX?
32+
[SPDX](https://spdx.dev/learn/overview/) (Software Package Data Exchange) is an open standard for communicating software bill of material information, including provenance, license, security, and other related information. SPDX reduces redundant work by providing common formats for organizations and communities to share important data, thereby streamlining and improving compliance, security, and dependability. The SPDX specification is recognized as the international open standard for security, license compliance, and other software supply chain artifacts as ISO/IEC 5962:2021.
33+
34+
OSSLibraries uses [SPDX License List](https://spdx.org/licenses/) to identify and display the license of every dependency.
35+
:::
36+
3137
## Requirements
3238

3339
- A HarmonyOS app built with ArkTS pages (ArkUI).

‎index.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,3 +62,9 @@ features:
6262
> ```
6363
>
6464
> :::
65+
66+
::: info What is SPDX?
67+
[SPDX](https://spdx.dev/learn/overview/) (Software Package Data Exchange) is an open standard for communicating software bill of material information, including provenance, license, security, and other related information. SPDX reduces redundant work by providing common formats for organizations and communities to share important data, thereby streamlining and improving compliance, security, and dependability. The SPDX specification is recognized as the international open standard for security, license compliance, and other software supply chain artifacts as ISO/IEC 5962:2021.
68+
69+
OSSLibraries uses [SPDX License List](https://spdx.org/licenses/) to identify and display the license of every dependency.
70+
:::

‎zh/guide/getting-started.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ pnpm add -D osslibraries-hvigor-plugin
7272
yarn add -D osslibraries-hvigor-plugin
7373
```
7474

75-
```sh [bun]
75+
```sh [Bun]
7676
bun add -D osslibraries-hvigor-plugin
7777
```
7878

‎zh/guide/introduction.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,12 @@ OSSLibraries 将维护工作交给构建过程:每次构建时插件检查真
3030
- 正确处理 SPDX 表达式(`Apache-2.0 OR MIT`)、常见拼写错误、同一依赖多版本等情况。
3131
- 运行时的两种选择:使用预定义页面,或使用核心 API 自建 UI。
3232

33+
::: info 什么是 SPDX?
34+
[SPDX](https://spdx.dev/learn/overview/)(Software Package Data Exchange,软件包数据交换标准)是一项用于交换软件物料清单信息的开放标准,涵盖来源、许可、安全及其他相关信息。SPDX 通过为组织和社区提供共享重要数据的通用格式,减少了重复工作,从而简化并提升了合规性、安全性和可靠性。SPDX 规范已被作为安全、许可合规性及其他软件供应链工件的国际开放标准(ISO/IEC 5962:2021)。
35+
36+
OSSLibraries 使用 [SPDX License List](https://spdx.org/licenses/) 来识别并展示每个依赖的许可证。
37+
:::
38+
3339
## 环境要求
3440

3541
- 一个基于 ArkTS 页面(ArkUI)构建的 HarmonyOS 应用。

‎zh/index.md‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,11 @@ features:
1717
- title: 端到端
1818
details: 从依赖扫描到应用内展示由同一条流水线完成,列表反映实际打包进 HAP 的依赖。
1919
- title: 开箱即用
20-
details: 注册一次 Hvigor 插件,每次构建都会根据当前 `oh_modules` 重新生成元数据。
20+
details: 注册一次 Hvigor 插件,每次构建都会根据当前 oh_modules 重新生成元数据。
2121
- title: 预定义 UI
2222
details: 基于 ArkUI 和 UI Design Kit 的列表页与详情页,导入页面即可通过命名路由访问。
2323
- title: 精准识别
24-
details: 完整解析 `Apache-2.0 OR MIT` 等 SPDX 表达式,并自动纠正常见的拼写错误。
24+
details: 完整解析 Apache-2.0 OR MIT 等 SPDX 表达式,并自动纠正常见的拼写错误。
2525
- title: 完整许可证全文
2626
details: 优先读取包内自带的 LICENSE 文件,缺失时回退到 SPDX 规范文本。
2727
- title: 自定义 UI
@@ -62,3 +62,9 @@ features:
6262
> ```
6363
>
6464
> :::
65+
66+
::: info 什么是 SPDX?
67+
[SPDX](https://spdx.dev/learn/overview/)(Software Package Data Exchange,软件包数据交换标准)是一项用于交换软件物料清单信息的开放标准,涵盖来源、许可、安全及其他相关信息。SPDX 通过为组织和社区提供共享重要数据的通用格式,减少了重复工作,从而简化并提升了合规性、安全性和可靠性。SPDX 规范已被作为安全、许可合规性及其他软件供应链工件的国际开放标准(ISO/IEC 5962:2021)。
68+
69+
OSSLibraries 使用 [SPDX License List](https://spdx.org/licenses/) 来识别并展示每个依赖的许可证。
70+
:::

0 commit comments

Comments
 (0)