OpenChain-Project / Telco-WG

This is the OpenChain Telco Work Group
Other
12 stars 6 forks source link

Allow SPDX 2.3 #77

Closed vargenau closed 6 months ago

MasahiroDAIKOKU commented 6 months ago

We agree that version 2.3 will be added to the list of acceptable SPDX versions and JSON will be added as a data format.

The impact of expanding the acceptable content in the Telco SBOM Guide is that companies in the more downstream supply chain will have more work to do, such as format conversion, when they receive SBOMs.

However, I think it is necessary to allow methods that are practical at the time and to update the document to keep up with the times with what is described.