[Defect]: relatedCryptographicAsset.type description is copied from securedBy.mechanism
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 91/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- json
- Domain
- documentation
Research direction
Open bom-1.7.schema.json and compare the description for relatedCryptographicAsset.type with securedBy.mechanism. Update the former to describe the referenced asset type, then verify that the wording matches the issue's proposed meaning and does not alter the existing securedBy description.
Written by the indexing model from the issue text.
Description
Describe the defect
In bom-1.7.schema.json, relatedCryptographicAsset.type is described as:
Specifies the mechanism by which the cryptographic asset is secured by.
This is the same sentence as securedBy.mechanism, which describes a different thing. The examples given for the field (publicKey, privateKey, algorithm) say what the referenced asset is, not how the component is protected.
The field is new in 1.7, and securedBy already existed in 1.6, so this looks like a copy when the field was added.
Additional context
A possible wording:
Specifies the type of the related cryptographic asset.
- Dominant language
- XSLT
- Stars
- 551
- Forks
- 93
- Avg merge
- 4h 51m
- Merged PRs (30d)
- 42
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CycloneDX/specification
-
defect documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
CycloneDX/specification#1115 ·
-
cap: cryptography-registry
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
CycloneDX/specification#1098 ·
-
CDX 2.0 documentation ready for review
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
CycloneDX/specification#1035 ·
-
cap: cryptography-registry defect
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
CycloneDX/specification#1028 ·
-
cap: cryptography-registry defect
Difficulty 1/5 Under an hour Newbie friendliness 86/100
CycloneDX/specification#918 ·
All issues in CycloneDX/specification
Similar issues
-
user-reported
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Kong/developer.konghq.com#7316 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
HarperFast/skills#96 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
infinispan/infinispan#18150 ·
-
bug triage:deciding
Difficulty 1/5 Under an hour Newbie friendliness 88/100
open-telemetry/otel-arrow#4132 ·
-
Ecosystem: ClawMetry — the Qwen Code reader is now free and open source (follow-up to #9294 / #9338) Opencategory/integration priority/P3 scope/documentation status/ready-for-human type/feature-request
Difficulty 1/5 Under an hour Newbie friendliness 84/100