You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The cdx namespace should include a property to hold the path of the file that produced the dependency.
Vendors have started included such a property in their namespaces; the lack of standardization around the storage of this information is creating a significant interoperability problem.
If this property is standardized, other SBOM producing tools will be more likely to include this information, and SBOM consumers will more likely use it.
The text was updated successfully, but these errors were encountered:
jkowalleck
changed the title
Standardized cdx namespace property for source file
[PROPOSAL] Standardized cdx namespace property for source file
Jun 7, 2023
The
cdx
namespace should include a property to hold the path of the file that produced the dependency.Vendors have started included such a property in their namespaces; the lack of standardization around the storage of this information is creating a significant interoperability problem.
For example, GitLab uses
gitlab:dependency_scanning:input_file:path
.If this property is standardized, other SBOM producing tools will be more likely to include this information, and SBOM consumers will more likely use it.
The text was updated successfully, but these errors were encountered: