We have a number of customers that want HBOM like data from us (i.e. a list of components), but they want to also know the country of origin of the component and currently the CDX HBOM does not appear to provide this information.
Proposal
Here's what I have in mind:
Add an optional property to the component with a "name" of "cdx:device:countryOfOrigin" (at least that's what it would be in SPDX JSON format).
Motivation
We have a number of customers that want HBOM like data from us (i.e. a list of components), but they want to also know the country of origin of the component and currently the CDX HBOM does not appear to provide this information.
Proposal
Here's what I have in mind:
Example: