Open prabhu opened 5 months ago
Currently it is possible to specify a value for scope without offering any evidence.
scope
https://github.com/CycloneDX/specification/blob/master/schema/bom-1.6.schema.json#L4783
This creates potential false negatives if consuming tools are configured to filter for components with specific scope values such as required
required
Thanks for the suggestion @prabhu. Any suggestions on a possible way to represent this? What kind of evidence would be necessary?
Currently it is possible to specify a value for
scope
without offering any evidence.https://github.com/CycloneDX/specification/blob/master/schema/bom-1.6.schema.json#L4783
This creates potential false negatives if consuming tools are configured to filter for components with specific scope values such as
required