transparency-exchange-api
transparency-exchange-api copied to clipboard
Should `formats` within an Artifact Collection be flattened?
mimeTypetells us theformat
There was a side discussion as to whether Artifact type is enough - as it does not allow us to understand which BOM is the SBOM for example.
Noting that various BOMs can have multiple purposes - i.e. a BOM can be both an SBOM, VDR and VEX. Some might just be an SBOM with VEX/VDR in a separate artifact.
I didn't think mimeType was used anymore as mime was specific to SMTP. Should be mediaType IMO. CycloneDX v2.0 is changing mime-type on a component to mediaType.
Yes, it's named Internet Media Types since a very long time.
https://www.iana.org/assignments/media-types/media-types.xhtml