CycloneDX / sbom-utility

Utility that provides an API platform for validating, querying and managing BOM data
Apache License 2.0
81 stars 13 forks source link

Support OWASP SCVS "Profiles" for use in validation, trimming, etc. commands #64

Open mrutkows opened 8 months ago

mrutkows commented 8 months ago

See standardized profiles: https://scvs.owasp.org/bom-maturity-model/profiles/examples/ntia-minimum-elements/

Also, see how they are being used in BOM generation (which could be used to create test/input data):

Note: profile usage/use cases will require some really good documentation to convey understanding with great references...