CycloneDX / CycloneDX/specification

Evidence for `component.scope`

Open
#437 1 comment 0 reactions 0 assignees View on GitHub
proposed core enhancement
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

Currently it is possible to specify a value for `scope` without offering any evidence.

https://github.com/CycloneDX/specification/blob/master/schema/bom-1.6.schema.json#L4783

This creates potential false negatives if consuming tools are configured to filter for components with specific scope values such as `required`

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.