The documentation that you can use any prefix for SPDX variable is wrong, since it isn't supported. One of the examples in https://docs.yoctoproject.org/dev/ref-manual/variables.html#term-SPDX_INVOKED_BY: ``` MY_COMPANY_name = "Acme Corp" MY_COMPANY_type = "organization" SPDX_IMAGE_SUPPLIER = "MY_COMPANY" SPDX_SDK_SUPPLIER = "MY_COMPANY" ``` From looking at the code, <PREFIX> isn't used at all in most of those variables, only the (taken from new_agent function in meta/lib/oe/sbom30.py): - <PREFIX>_name - <PREFIX>_type - <PREFIX>_import - <PREFIX>_comment - <PREFIX>_id_* (all of the options in oe.spdx30.ExternalIdentifierType.NAMED_INDIVIDUALS) - only _email is mentioned in documentation - <PREFIX>_ref - not mentioned at all, works "somewhat" like what documentation says setting prefix does. The issue applies to (either mentioned directly, or by linking to, usually, SPDX_IMAGE_SUPPLIER): - SPDX_IMAGE_SUPPLIER - SPDX_PACKAGE_SUPPLIER - SPDX_SDK_SUPPLIER - SPDX_INVOKED_BY - SPDX_ON_BEHALF_OF The patch that I posted (https://lists.openembedded.org/g/openembedded-core/topic/patch_v2/120910416) tried to change the code to match the documentation but based on the Joshua comment: https://lists.openembedded.org/g/openembedded-core/message/244245 it's the documentation that needs to be fixed not the code. Steps to reproduce the issue: - try to use documented example (the one I mentioned in the beginning) and check if generated SPDX contains `Acme Corp`
Fixed in: 24f7a2b25 ("ref-manual/variables.rst: Fix the documentation for the SPDX agent variables") f7273b885 ("ref-manual/variables.rst: Document SPDX_AUTHORS") of yocto-docs