Open justinabrahms opened 1 year ago
SPDX: https://spdx.github.io/spdx-spec/v2.3/how-to-use/#k22-mapping-ntia-minimum-elements-to-spdx-fields
Also, section 2.3 of https://www.ntia.gov/files/ntia/publications/framingsbom_20191112.pdf
Can't seem to find anything authoritative on NTIA+CycloneDX, but we should be able to map SPDX fields to the CDX format.
I'm not entirely clear if requiring package supplier makes sense.
@justinabrahms -- I think you're right to be unsure of whether to use package supplier in a NTIA minimum elements-related check. While it is technically part of the minimum elements, it seems, in my experience, that very few SBOMs actually include it, partially because the definition of a "supplier" for many open source software components is ambiguous.
https://www.ntia.gov/sites/default/files/publications/sbom_minimum_elements_report_0.pdf
minimum elements