sbom-everywhere
sbom-everywhere copied to clipboard
SBOM naming updates
@sjn pointed out during the meeting that there are some new things we should update the naming document with
Examples
- Website default location (similar to .well-known)
- Repository locations
- Filesystem locations (like how we store license details in a distro)
Some simple guidelines to help
Kate thinks the FSFE has similar guidance, if they do, we should link to that
FSFE's reuse specification version 3.3 talks about .reuse and LICENSES. Maybe too narrow naming for what's suitable for metadata in general, no?