CycloneDX / CycloneDX/specification

Unclear definition of serialNumber and version

Open
#363 4 comments 1 reaction 0 assignees View on GitHub
question
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

I find the interaction between the `serialNumber` and `version` of a BOM very unclear.

The definition in CycloneDX 1.5 says (highlighting mine):

- `serialNumber`
> Every BOM generated SHOULD have a unique serial number, **even if the contents of the BOM have not changed over time**. If specified, the serial number MUST conform to RFC-4122. Use of serial numbers are RECOMMENDED.
- `version`
> Whenever an existing BOM is modified, either manually or through automated processes, the version of the BOM SHOULD be incremented by 1. **When a system is presented with multiple BOMs with identical serial numbers, the system SHOULD use the most recent version of the BOM**. The default version is '1'.

The first implies that any time a BOM is written (even if nothing has changed), it gets a new serial. The second implies that the same serial can exist in several versions.

Given the definition of `serialNumber`, in which scenario would I modify a BOM and keep the old serial while incrementing the version?

Some other resources discussing `serialNumber` are #11 and #97 but in neither do I find an answer.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.