Investigate if custom registries should result in purl's with a different type from "cargo" #231
Labels
cargo-cyclonedx
Issues related to the Cargo SBOM generation application
enhancement
New feature or request
From #226's
The purl specification does not indicate a required type specific to Rust, beyond
Investigate what other CycloneDX tools are doing, particularly if they support private repositories. Rust supports private registries and indicates at a per-dependency level what registry it comes from, so we should be able to access this information if we want to use that as the purl's
type
for a dependency component and the[package]
'spublish
list for the package's componentThe text was updated successfully, but these errors were encountered: