bom-examples icon indicating copy to clipboard operation
bom-examples copied to clipboard

A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)

Results 9 bom-examples issues
Sort by recently updated
recently updated
newest added

Many new fields (schema) were added to between v1.3 and v1.4 yet there are not examples that ref. v1.4. In addition, we would like examples that exhibit the use of...

As an enhancement, it would be useful to be publish SBOM examples for 2 versions of the same OSS project. It does not really matter which project is chosen. Dropwizard...

in https://github.com/CycloneDX/bom-examples/tree/master/VEX/CISA-Use-Cases/Case-7 boms do not contain version of the software, but vex file affects sections contain versions or version ranges (i.e. https://github.com/CycloneDX/bom-examples/blob/7d529848e2f8bd65d03aec9eab16f139fd445ff4/VEX/CISA-Use-Cases/Case-7/vex.json#L169). So if I understand correctly, this vex should...

Hello, I can't find examples of SBOM where the "component" type is "file" and some component has related components. Could you please provide such examples?

@stevespringett - thanks for putting this example together. When reviewing the vulnerability/analysis/response field, I saw that it contained "["will_not_fix", "update"]". Is this correct? According to the CycloneDX standard, this entry...