liboqs
liboqs copied to clipboard
Update CBOM to CycloneDX 1.6 specification
The specification used for CBOMs has been upstreamed to CycloneDX 1.6: https://github.com/CycloneDX/specification/releases/tag/1.6
This issue is to update the CBOM in liboqs, and its generation script to the CycloneDX 1.6 specification.
As per https://github.com/open-quantum-safe/liboqs/pull/1708#issuecomment-2069210942 also document CBOM utility, use and development/developer's implications.
See also https://github.com/open-quantum-safe/liboqs/issues/1831
I missed this issue when originally opening the above - apologies. I added some observations. We can close one, though I did try to add my non-expert comments. @bhess let me know if you want any help with this.
Closing this issue as a dupe of #1831.