CycloneDX / CycloneDX/specification
Evidence for `component.scope`
Open
proposed core enhancement
- Dominant language
- XSLT
- Stars
- 547
- Forks
- 93
- Avg merge
- 7h 11m
- Merged PRs (30d)
- 37
Description
Currently it is possible to specify a value for `scope` without offering any evidence.
https://github.com/CycloneDX/specification/blob/master/schema/bom-1.6.schema.json#L4783
This creates potential false negatives if consuming tools are configured to filter for components with specific scope values such as `required`
Contributor guide
Assessment
This issue has not been assessed yet.