SBOM clarifications on various usecases
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 30/100
- Issue type
- Documentation
- Clarity
- Needs clarification
- Activity status
- Active
- Domain
- documentation
Research direction
The issue asks for clarification on CycloneDX representation for components appearing in multiple locations and nested within other components. Start by reading the CycloneDX specification documentation, particularly sections on components, dependencies, and bom-ref. Look for existing examples or similar issues in the repository. Determine the recommended approach by analyzing the spec and possibly consulting existing SBOM examples. The outcome should be a clear answer to the two scenarios described, referencing the spec.
Written by the indexing model from the issue text.
Description
- Same component in multiple locations:
If the same component occurs in multiple locations within an application/package, should we define the component only once in the components section and represent all its occurrences/locations within that component (for example, using multiple locations), or should we create a separate component entry for each occurrence?
2.I have a production build ZIP for a product. The product bundles HBase, and HBase itself contains a.jar. The same a.jar is also present at another location within the production build.
In the SBOM, HBase is represented as a separate component. In this scenario, should a.jar also be represented as a separate component with its own bom-ref, and should we specify a.jar as a dependency of HBase in the dependencies section?
Or, since a.jar is physically bundled inside HBase, should a.jar be represented as a nested component under HBase instead?
Also, if the same a.jar occurs at another location in the product, should both occurrences reference the same component definition, with the locations captured separately?
What is the recommended CycloneDX representation for this scenario? @jkowalleck @stevespringett
- Dominant language
- XSLT
- Stars
- 551
- Forks
- 93
- Avg merge
- 4h 51m
- Merged PRs (30d)
- 42
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CycloneDX/specification
-
Response vs Responce Open
Difficulty 1/5 Under an hour Newbie friendliness 68/100
CycloneDX/specification#1121 ·
-
defect documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
CycloneDX/specification#1115 ·
-
cap: cryptography-registry
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
CycloneDX/specification#1098 ·
-
defect
Difficulty 1/5 Under an hour Newbie friendliness 91/100
CycloneDX/specification#1045 · 2 comments ·
-
CDX 2.0 documentation ready for review
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
CycloneDX/specification#1035 ·
All issues in CycloneDX/specification
Similar issues
-
Link Checker Report Openautomated issue report
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Humanity AI Open
Difficulty 1/5 Under an hour Newbie friendliness 90/100
numfocus/project-fundraising#166 ·
-
area:proxy bug security severity:low track:open-source
Difficulty 2/5 1-3 hours Newbie friendliness 70/100