CycloneDX / specification

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX
https://cyclonedx.org/
Apache License 2.0
359 stars 56 forks source link

Support for sustainability attributes #312

Open prabhu opened 11 months ago

prabhu commented 11 months ago

Inspired by this blog on the web sustainability, it would be nice to tag components and services based on factors such as (replicated from the blog):

Capturing this information in a structured manner can help organizations and individuals make informed decisions when it comes to vendor or package selection, benchmarking against peers, or capturing the current and to-be state for maturing in sustainability.

Components and Services can be independently attested and verified for sustainability.

stevespringett commented 11 months ago

Could we start capturing this via properties? There seems to be a lot of possible use cases and an extremely large taxonomy of different types of data that could potentially be captured. My thinking is that if we wait to identify them all, it will be a multi-year process. We could with a small set of properties and expand over time independent of the specification. Once completely flushed out, we could standardize their representation in the specification itself.

jkowalleck commented 11 months ago

Want to get going with property taxonomy? come to https://github.com/CycloneDX/cyclonedx-property-taxonomy and have some peers involved.

prabhu commented 11 months ago

My cunning plan is to get some data from AWS and Google Cloud users and start creating a list of cloud services' carbon emissions to start with.

https://aws.amazon.com/aws-cost-management/aws-customer-carbon-footprint-tool/ https://cloud.google.com/carbon-footprint?hl=en