CycloneDX / CycloneDX/specification

[FEATURE]: Standard grouping (CBOM related)

Open
#669 4 comments 0 reactions 0 assignees View on GitHub
cap: cryptography proposed core enhancement
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

There is a need to group cryptographic assets (possibly others) into a standard.

For example, the following can currently be represented:
- Use of a cryptographic algorithm for encryption (e.g. AES-256)
- Use of a cryptographic algorithm for signing (HS-256)
- Use of a `token` defined in relatedCryptoMaterial

What cannot be represented is the overall "standard" that these are part of. In this case JOSE. The current workaround is to leverage CycloneDX Properties.

Grouping these together into a standard would provide much more context into how these three seemingly independent components are used.

This was discussed in the [CycloneDX Cryptography Working Group call on 2025-08-07](https://www.youtube.com/watch?v=L-WgplNs_R8&list=PLqjEqUxHjy1WebDhYC_7-zDzGy8EqAqpP).

cc: @IanDeaks, @n1ckl0sk0rtge, @bhess

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.