aboutcode-org / aboutcode-org/scancode.io

Need to refine and report CycloneDX SBOM metadata

未关闭
#1,343 3 条评论 0 个 reaction 已指派 2 人 已被 @tdruez 认领 在 GitHub 查看
design-needed medium priority
主要语言
Python
星标
215
派生
203
平均合并
4 天 8 小时
30 天内合并 PR
6

描述

For a CycloneDX SBOM (v1.4 to v1.6) you can report a component in the "metadata" section (header) in addition to the "components" section (details). This component represents "The component that the BOM describes". It has the same attributes (including PURL) as a component in the body of the SBOM. This top-level component might be a container (pkd:oci) or other software package.

We need to:
1. Capture this metadata/component (header) data separately from the components (details) data and
2. Capture and report other CycloneDX header information such as:
- bomFormat
- specVersion
- metadata/authors
- metadata/properties
- metadata/timestamp
- metadata/tools

Unfortunately the data elements of an SPDX v2.3 Document are very different and I cannot figure out the analogy for SPDX 3.0. We probably need some CDX-specific data structure or possibly we just capture this as some blob of data with key-value pairs.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。