Proposal: a `runtime` component type
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 85/100
- Issue type
- Feature
- Clarity
- Clearly specified
- Activity status
- Active
- Domain
- documentation
Research direction
Locate the component.type enumeration in the CycloneDX specification schema (likely in the XML or JSON schema definitions). Add runtime as a new enum value with the provided definition. Update any relevant documentation or examples. Done when the specification includes the new type and all validation passes.
Written by the indexing model from the issue text.
Description
Context. On cyclonedx-property-taxonomy#175 the AI/ML working group advised that "the thing that runs a model" is not an AI-specific property and should be pursued as a component.type value, with the model-to-runtime relationship expressed in a formula. Opening the question here as suggested.
Proposal. Add runtime to the component.type enumeration, defined as a component whose function is to load and execute other components (models, functions, bytecode) at run time. Distinct from application (a deliverable that is run), framework (linked into an application) and platform (the environment an application runs on). Examples: vLLM, Triton Inference Server, NVIDIA NIM, Ray Serve, a JVM, a WASM runtime.
Why an enum value rather than a property. Consumers filtering a BOM for "what executes this model" need a first-class type; a property under one producer's namespace does not generalize across producers. The runtime-to-model relationship is then a formula or dependency edge, which answers "which runtime serves which model" without new properties.
Prior art. k8s-aibom, a runtime inventory controller for Kubernetes, emits runtimes today as application components with a runtime:name property and would switch to the new type on adoption. Other runtime-observing producers face the same choice.
Open question for the group. Whether runtime should be a new value or a refinement of platform. The distinction we found useful in practice: a platform hosts an application, a runtime executes an artifact that is itself a component in the BOM.
- Dominant language
- XSLT
- Stars
- 558
- Forks
- 93
- Avg merge
- 19h 7m
- Merged PRs (30d)
- 17
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CycloneDX/specification
-
[Defect]: FFDH pattern treats ephemeral E as requiredPossibly taken @Mehrn0ush claimed this 2 days ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 82/100
CycloneDX/specification#1147 ·
Maintainers usually reply within 1 day
-
Response vs ResponceOpen
Difficulty 1/5 Under an hour Newbie friendliness 68/100
CycloneDX/specification#1121 · 1 comment ·
Maintainers usually reply within 1 day
-
defect documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
CycloneDX/specification#1115 ·
Maintainers usually reply within 1 day
-
[FEATURE]: Add EAX mode to Cryptography RegistryPossibly taken @jvdsn claimed this 31 days ago. Opencap: cryptography-registry
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
CycloneDX/specification#1098 ·
Maintainers usually reply within 1 day
-
defect
Difficulty 1/5 Under an hour Newbie friendliness 91/100
CycloneDX/specification#1045 · 2 comments ·
Maintainers usually reply within 1 day
All issues in CycloneDX/specification
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Table: Space fires onActivate in single-selection mode — the reference doc and the JSDoc disagreeOpen
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
sidorares/react-x11-components#764 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 71/100
t4t5/omdrop-owl#14 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 91/100
githubnext/gh-aw-workshop#4458 ·
Maintainers usually reply within 1 day
-
bug:new
Difficulty 1/5 Under an hour Newbie friendliness 84/100
callstackincubator/simlock#451 ·
Maintainers usually reply within 1 day