CycloneDX / CycloneDX/specification

[FEATURE]: Add external reference type for support policy/lifecycle metadata

Open
#591 5 comments 1 reaction 1 assignee Claimed by @ppkarwasz View on GitHub
proposed core enhancement
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

## Describe the feature

While the work on CLE is progressing it would be useful to add an [`externalReference` type](https://cyclonedx.org/docs/1.6/json/#externalReferences_items_type) to hold a link to a CLE, OpenEOX or other kind of document that describes the versioning/support policy of the project.

## Possible solutions

Naming is certainly the most difficult problem, but the new type might be called `support-lifecycle` or simply `lifecycle`.

Currently there is no machine-readable format to describe EOS/EOL data, but the link could point to a human-readable page.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.