ietf-scitt / charter

Documentation of initial IETF Supply Chain Integrity Transparency and Trust (SCITT) WG Charter
6 stars 13 forks source link

Charter proposal comment #9

Open rjb4standards opened 2 years ago

rjb4standards commented 2 years ago

The proposed charter contains this statement: A single product is composed of multiple sub-products coming from different suppliers. There is no agreed-upon standard to compose information from different producers."

An SBOM, in either SPDX or CycloneDX format provides information about components contained in a software product. May want to consider a reference to these two SBOM standards, within the context of the above statement

henkbirkholz commented 2 years ago

@rjb4standards, I assume the current charter text addresses this issue in an appropriate manner now. Could you please confirm?