clarify use of "provenance" as it relates to NIST vs SLSA,etc
Open
t: SBOM
- Dominant language
- CSS
- Stars
- 9
- Forks
- 12
- Avg merge
- 12h 20m
- Merged PRs (30d)
- 21
Description
during the specification meeting, when reviewing the Terms and Definitions, it was called out that the usage of "provenance" is very specific to NIST and differs from the SLSA,etc definition. while the spec is not a good place for this information, the guide is likely a place to call this out as it will likely help clarify the term, esp for people coming from the supplychain security space who may be more familiar with the SLSA definition.
Contributor guide
Assessment
This issue has not been assessed yet.