specification
specification copied to clipboard
BC: Removing `incomplete_` prefix in compositions.aggregate
https://cyclonedx.org/docs/1.5/json/#compositions_items_aggregate
We currently have incomplete_ prefix on values. This sounds negative and could confuse the consumers that the list is incomplete.
For example, the vendor might have provided a complete and accurate first-party-only or third-party-only SBOM as per the compliance requirements.
It will be nice to accept values without the incomplete_ prefix.
This sounds negative and could confuse the consumers that the list is incomplete.
It is incomplete. If I were to purchase an energy bar and the manufacture only included the ingredients from third-parties and not their own, the ingredient list would be incomplete.