CycloneDX / CycloneDX/cyclonedx-php-composer

render property `cdx:reproducible`

Open
#396 0 comments 0 reactions 0 assignees View on GitHub
enhancement good first issue hacktoberfest
Dominant language
PHP
Stars
87
Forks
7
PR merge metrics
No merged PRs in 30d

Description

## Is your feature request related to a problem? Please describe.

If a BOM was generated as reproducible, this should be easily visible from the BOM.
Therefore, https://github.com/CycloneDX/cyclonedx-property-taxonomy/pull/70 exists

## Describe the solution you'd like

Property `cdx:reproducible` is added under `metadata.properties`.
Value is `true`, if BOM was build in reproducible mode, else value is `false`.

## Describe alternatives you've considered

Property `cdx:reproducible` could also be added under global `properties`, which exists since CDX1.5.
This global space does not exist as long as `metadata.properties`, which exists since CDX1.3.
For a better compatibility version-downwards, let's use the area that exists longer.

## Additional context

Idea: use the `metadata.properties`, because the `metadata` also houses the timestamp of document creation.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.