Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Need standardized API for TEA Artifact downloading

Open
#246 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Quiet

Research direction

Start by reviewing the existing formats object and its url field, then consult the Ecma meeting discussion from 2026-05-06. Define the standardized download API, including how it relates to the external-URL fallback and authentication, and document the completed API behavior in the specification.

Written by the indexing model from the issue text.

Description

Prio 1 TEA Artifact

As discussed on the Ecma meeting on 2026-05-06, we need standardized API to download TEA Artifacts (i.e., actual SBOM content).

Currently, we have url field under formats that allows to specify external URL to download TEA Artifact. However, this should be considered as a fallback option only - under the assumption that such URL is either publicly available or is using same authn/z as the TEA server itself.

Dominant language
Shell
Stars
116
Forks
23
Avg merge
2d 11h
Merged PRs (30d)
63

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from CycloneDX/transparency-exchange-api

All issues in CycloneDX/transparency-exchange-api

Similar issues

More Shell/Bash issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.