cdfoundation / sig-security-sbom

SIG Security - Software Bill of Materials
Apache License 2.0
18 stars 5 forks source link

Add a package ArtifactType #11

Open goneall opened 4 years ago

goneall commented 4 years ago

There are several attributes specific to a package which are not captured in the other artifact types (e.g. download location, home page).

SPDX currently has these fields in the Package class. Not having these fields would create a compatibility issue.

CASTResearchLabs commented 4 years ago

the current proposition would handle any additional information as annotation this was an attempt to keep the model lean

goneall commented 4 years ago

These attribute are important to be standardized for proper interchange for many use cases. Yes, you can have them as annotations or even comments, but then we loose the value of the standard.