specification
specification copied to clipboard
Evidence for `component.scope`
Currently it is possible to specify a value for scope without offering any evidence.
https://github.com/CycloneDX/specification/blob/master/schema/bom-1.6.schema.json#L4783
This creates potential false negatives if consuming tools are configured to filter for components with specific scope values such as required
Thanks for the suggestion @prabhu. Any suggestions on a possible way to represent this? What kind of evidence would be necessary?