CycloneDX / CycloneDX/specification
[FEATURE]: Add external reference type for support policy/lifecycle metadata
Open
proposed core enhancement
- Dominant language
- XSLT
- Stars
- 547
- Forks
- 93
- Avg merge
- 7h 11m
- Merged PRs (30d)
- 37
Description
## Describe the feature
While the work on CLE is progressing it would be useful to add an [`externalReference` type](https://cyclonedx.org/docs/1.6/json/#externalReferences_items_type) to hold a link to a CLE, OpenEOX or other kind of document that describes the versioning/support policy of the project.
## Possible solutions
Naming is certainly the most difficult problem, but the new type might be called `support-lifecycle` or simply `lifecycle`.
Currently there is no machine-readable format to describe EOS/EOL data, but the link could point to a human-readable page.
Contributor guide
Assessment
This issue has not been assessed yet.