-
Notifications
You must be signed in to change notification settings - Fork 0
[3.8] Relationship to SBOM / HBOM & layering #8
Copy link
Copy link
Open
Labels
aspect:layering3.8 Relationship to SBOM/HBOM & layering3.8 Relationship to SBOM/HBOM & layeringneeds:ownerNo aspect owner assigned yetNo aspect owner assigned yetstatus:deliberatingOpen argument — options being exploredOpen argument — options being exploredtype:decisionA concrete choice to be resolvedA concrete choice to be resolved
Metadata
Metadata
Assignees
Labels
aspect:layering3.8 Relationship to SBOM/HBOM & layering3.8 Relationship to SBOM/HBOM & layeringneeds:ownerNo aspect owner assigned yetNo aspect owner assigned yetstatus:deliberatingOpen argument — options being exploredOpen argument — options being exploredtype:decisionA concrete choice to be resolvedA concrete choice to be resolved
Type
Fields
Give feedbackNo fields configured for issues without a type.
Aspect
Section: 3.8 Relationship to other inventories and layering
Orientation relevance: both
Objective
Decide how a profile expresses the relationship between cryptographic assets and the software
and hardware that use them, including links to an accompanying SBOM and, where relevant, HBOM.
Background & links
Scoping document §3.8. A CBOM is rarely used alone; its value depends on being relatable to
the components it describes. References: SBOM/CBOM relationship; purl / BOM-ref for component
identity.
Options under consideration
(purl / BOM-ref); component detail stays in the SBOM/HBOM. (Trade-off: clean separation;
requires the linked artifacts to be present.)
standalone use. (Trade-off: usable alone; risk of drift between artifacts.)
Open questions
Dependencies
Depends on attribute model (3.3 #1); coordinates with normalisation (3.7 #3) on
identifiers.
Decision
Not yet decided.
Impact on the specification
Spec section "Relationship to SBOM/HBOM and layering."