CycloneDX / specification

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX
https://cyclonedx.org/
Apache License 2.0
361 stars 57 forks source link

Add support for license acknowledgements #407

Closed stevespringett closed 6 months ago

stevespringett commented 6 months ago

CycloneDX should support both declared and concluded licenses. Currently, the license acknowledgement is undefined and there is no way to communicate this. Observed licenses are already supported in evidence.licenses, so no need to expand upon that.