You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The resource_uri is currently a purl, but there is no guidance on how to construct it. It would be useful to provide better guidance for it. A few things to think about:
public registry vs private company's software. Not all a company's software is distributed via a public registry. It's unclear how the purl should be constructed for the latter
compulsory version. Without a version, rollback attacks are possible. Version / tag is available in provenance, so we ought to make it available in the purl as well, I think.
monorepos. They don't have versions per se. I think their releases still adhere to some versioning scheme (semver, calver, etc)
The text was updated successfully, but these errors were encountered:
The resource_uri is currently a purl, but there is no guidance on how to construct it. It would be useful to provide better guidance for it. A few things to think about:
The text was updated successfully, but these errors were encountered: