Festo-se / cyclonedx-editor-validator

Tool for creating, modifying and validating CycloneDX SBOMs.
https://festo-se.github.io/cyclonedx-editor-validator/
GNU General Public License v3.0
18 stars 4 forks source link

Rework merge-vex, s.t. a SBOM is not required #35

Open italvi opened 1 year ago

italvi commented 1 year ago

See https://github.com/CycloneDX/bom-examples/tree/master/VEX.

VEX and SBOM should be separate from each other.

italvi commented 5 months ago

As discussed in #156, merge-vex should just be included in merge.