CycloneDX / CycloneDX/sbom-utility
Support OWASP SCVS "Profiles" for use in validation, trimming, etc. commands
Open
documentation
enhancement
- Dominant language
- Go
- Stars
- 163
- Forks
- 21
- PR merge metrics
- No merged PRs in 30d
Description
See standardized profiles: https://scvs.owasp.org/bom-maturity-model/profiles/examples/ntia-minimum-elements/
Also, see how they are being used in BOM generation (which could be used to create test/input data):
- https://github.com/CycloneDX/cdxgen and its "--profile" flag/option.
Note: profile usage/use cases will require some really good documentation to convey understanding with great references...
Contributor guide
Assessment
This issue has not been assessed yet.