CycloneDX / CycloneDX/specification

Improve documentation for BOM-Link externalReferences.type

Open
#446 0 comments 0 reactions 0 assignees View on GitHub
documentation
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

Currently, externalReferences supports both URL and BOM-Link. There are some types that are better expressed with BOM-Link and therefore must be preferred over a URL.

Below are some types:

- bom
- release-notes
- model-card
- formulation
- attestation
- vulnerability-assertion
- pentest-report

To start with we can improve the documentation and create use-case examples to better illustrate the use of CycloneDX for these types.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.