Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable ORT to generate CycloneDX 1.6 SBOMs #8505

Closed
tsteenbe opened this issue Apr 9, 2024 · 2 comments
Closed

Enable ORT to generate CycloneDX 1.6 SBOMs #8505

tsteenbe opened this issue Apr 9, 2024 · 2 comments
Labels
enhancement Issues that are considered to be enhancements reporter About the reporter tool

Comments

@tsteenbe
Copy link
Member

tsteenbe commented Apr 9, 2024

Enabling generation of CycloneDX 1.6 SBOMs will be useful for license compliance as 1.6 supports both concluded and declared licenses. We should make a decision on which SBOM spec version we going to support - ideally develop a option for users to able to select a specific spec version such as CycloneDX [1.4, 1.5 or 1.6] or SPDX [2.2, 2.3 or 3.0]

See also
CycloneDX/specification#407
https://github.com/CycloneDX/specification/blob/1.6-dev/schema/bom-1.6.proto
https://github.com/CycloneDX/specification/blob/1.6-dev/schema/bom-1.6.schema.json
https://github.com/CycloneDX/specification/blob/1.6-dev/schema/bom-1.6.xsd

@tsteenbe tsteenbe added enhancement Issues that are considered to be enhancements reporter About the reporter tool labels Apr 9, 2024
@sschuberth
Copy link
Member

sschuberth commented Apr 9, 2024

@sschuberth
Copy link
Member

Resolved by #8645, though as discussed in the ORT community meeting, ORT sticks to writing CycloneDX 1.5 by default until there is wider adoption for CycloneDX 1.6. Users can customize the CycloneDX schema version via the reporter-specific schema.version option as mentioned e.g. here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Issues that are considered to be enhancements reporter About the reporter tool
Projects
None yet
Development

No branches or pull requests

2 participants