sbomasm
sbomasm copied to clipboard
Prefer purl as bom-ref
It would be great to be able to use the purl as the bom-ref if it exists. Its unique in a bom in general and I see this pattern in more tools. And if there already is a bom-ref and it can be kept unique in the document don't alter it. For example in assemble command every bom-ref is rewritten.
Looks interesting Point :+1: .
Btw, I agree with you on this:
assemble command every bom-ref is rewritten
I think we can use PURL as bom-ref for CycloneDX atleast, as almost every CycloneDX format SBOM have this format.