What exactly is the meaning of metadata.supplier? #521
-
https://cyclonedx.org/docs/1.6/json/#metadata_supplier
i.e. it makes a statement about the component itself not about the BOM. However, in line with this: Thus, in my opinion either the meaning should be changed to
or it should be deprecated in favor of component.supplier. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
@CycloneDX/core-team agrees on that, too. |
Beta Was this translation helpful? Give feedback.
-
this discussion duplicates #345 |
Beta Was this translation helpful? Give feedback.
@CycloneDX/core-team agrees on that, too.
But we cannot simply change the meaning of an existing field. see #379 (comment)
We could deprecate the existing
$.metadata.supplier
in favor of$.metadata.component.supplier
,and we could add a new field to
$.metadata
to represent the SBOM supplier.