- 
          
 - 
                Notifications
    
You must be signed in to change notification settings  - Fork 74
 
Closed
Labels
Description
I am still uncertain which elements allow the use of bomlink.
From use cases it appears to be possible in externalReferences[].url, vulnerabilities[].affects[].ref.
Any where else?
I'd suggest enhancing the schema to make it visible where a bomlink is allowed and where it is not.
This helps tool builders, parsers, and most importantly clarifies this from schema, not only some additional pamphlets/texts.