CycloneDX / CycloneDX/cyclonedx-dotnet-library

Flat merging can result in duplicate BOM refs

Open
#82 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
C#
Stars
28
Forks
35
PR merge metrics
No merged PRs in 30d

Description

Not sure how to handle this. For hierarchical merging the top level component information can be used to "namespace" BOM refs.

Maybe requires supporting passing in namespace values for each BOM or optionally generating a random namespace.

I personally don't like the latter as it will drastically change BOM refs between runs. But maybe that's not really an issue given they are just used to identify elements within a single instance of a BOM.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing flat merging and how BOM refs are assigned, then compare this with hierarchical merging and its use of top-level component information for namespacing. Done means the project has an agreed, deterministic way to prevent duplicate BOM refs when BOMs are flat-merged.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
tooling
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.