specification
specification copied to clipboard
`organizationalContact` enhancements
Consider enhancing organizationalContact to support the following:
- public gpg key bom-ref - This is especially useful to verify publishers and identify all components published with the same key. Tools must first create a component of type
cryptographic-assetand use that bom-ref in the contact attribute - tags - Tags such as
maintaineror git user ids can help locate the contact and their published components faster