Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Proposal: a `runtime` component type

Open Beginner friendly
#1,145 4 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
85/100
Issue type
Feature
Clarity
Clearly specified
Activity status
Active
Domain
documentation

Research direction

Locate the component.type enumeration in the CycloneDX specification schema (likely in the XML or JSON schema definitions). Add runtime as a new enum value with the provided definition. Update any relevant documentation or examples. Done when the specification includes the new type and all validation passes.

Written by the indexing model from the issue text.

Description

Context. On cyclonedx-property-taxonomy#175 the AI/ML working group advised that "the thing that runs a model" is not an AI-specific property and should be pursued as a component.type value, with the model-to-runtime relationship expressed in a formula. Opening the question here as suggested.

Proposal. Add runtime to the component.type enumeration, defined as a component whose function is to load and execute other components (models, functions, bytecode) at run time. Distinct from application (a deliverable that is run), framework (linked into an application) and platform (the environment an application runs on). Examples: vLLM, Triton Inference Server, NVIDIA NIM, Ray Serve, a JVM, a WASM runtime.

Why an enum value rather than a property. Consumers filtering a BOM for "what executes this model" need a first-class type; a property under one producer's namespace does not generalize across producers. The runtime-to-model relationship is then a formula or dependency edge, which answers "which runtime serves which model" without new properties.

Prior art. k8s-aibom, a runtime inventory controller for Kubernetes, emits runtimes today as application components with a runtime:name property and would switch to the new type on adoption. Other runtime-observing producers face the same choice.

Open question for the group. Whether runtime should be a new value or a refinement of platform. The distinction we found useful in practice: a platform hosts an application, a runtime executes an artifact that is itself a component in the BOM.

Dominant language
XSLT
Stars
558
Forks
93
Avg merge
19h 7m
Merged PRs (30d)
17

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from CycloneDX/specification

All issues in CycloneDX/specification

Similar issues

More Documentation issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.