CycloneDX / CycloneDX/specification

CycloneDX 2.0

Open
#631 5 comments 4 reactions 0 assignees Claimed by @stevespringett View on GitHub
breaking-changes CDX 2.0 proposed core enhancement
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

CycloneDX 2.0 is a major version in active development, focused on cleaning up legacy constructs, enforcing semantic correctness, and enabling modern schema reuse and API integration. This issue tracks the scope, rationale, and technical direction of the 2.0 release.

### Goals
- Modularize the specification into multiple schemas (e.g. bom, component, metadata, common, etc)
- Remove deprecated fields and legacy aliases
- Constrain properties to their correct types (e.g. cryptoProperties only on cryptographic assets)
- JSON-first focus supporting JSON Schema Draft 2020-12; potentially remove XML support
- Make the schema directly usable as a canonical model for the Ecma Transparency Exchange API
- Normalize naming and structural inconsistencies

----

- see milestone: https://github.com/CycloneDX/specification/milestone/2
- see release PR: https://github.com/CycloneDX/specification/pull/652

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.