Skip to content

Add support for attestations #192

@stevespringett

Description

@stevespringett

Myself and others in the OWASP community have been thinking about the need for a general purpose attestation format. Many of us have searched for existing format, without much success. Several industry-specific formats, many human readable formats, both no general purpose machine readable formats seem to exist. Having a standardized attestation format is crucial to scale many of the U.S. and world government efforts around SBOM and secure development and operational practices. Fortunately for us, someone in our very own community has started work on this very thing. It's simple, flexible, and prescriptive, just like CycloneDX is.

This ticket is an enhancement request to add BoA (Bill of Attestations) support to the core spec.

CycloneDX v1.5 has already added support for an attestation external reference, so externalizing BoA from the SBOM would already be possible with v1.5. So it should fit in nicely.

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions