Skip to content

Improve the value of the "documentDescribes" field in a generated SPDX 2.3 SBOM #564

@DennisClark

Description

@DennisClark

At the recent SPDX Docfest, it was pointed out that the value we provide in the SPDX 2.3 SBOM for the "documentDescribes" field is a self-reference to the SPDX Document, rather than the subject of the SBOM: SPDXRef-DOCUMENT .

It would be better to provide a filename (possibly even a PURL when available) to identify (describe?) the overall subject of the SBOM. See attached.

Screen Shot 2022-11-30 at 13 02 45

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions