+1

I've been reading up on the CycloneDX standards and other relevant material. Based on what I have understood so far, this release looks good to me. One minor suggestion (not for this release, but maybe future ones) is whether we should use "*.bom.json" as the file/artifact names instead of the current "*.cyclonedx.json". When I first heard about cyclonedx it wasn't clear to me what it was, but BOM on the other hand is a bit more known term. Plus, as per https://github.com/CycloneDX/specification#recognized-file-patterns , "bom.json" is a recognized file pattern for such files. So perhaps we should consider that name?

-Jaikiran

On 31/05/26 9:42 pm, Stefan Bodewig wrote:
I want to point out

https://repository.apache.org/content/repositories/orgapacheant-1070/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json
https://dist.apache.org/repos/dist/dev/ant/antlibs/cyclonedx/binaries/apache-ant-cyclonedx-0.1-bin-withdeps.tar.bz2.cyclonedx.json
https://dist.apache.org/repos/dist/dev/ant/antlibs/cyclonedx/binaries/apache-ant-cyclonedx-0.1-bin.tar.bz2.cyclonedx.json
https://dist.apache.org/repos/dist/dev/ant/antlibs/cyclonedx/source/apache-ant-cyclonedx-0.1-src.tar.bz2.cyclonedx.json

and their XML siblings.

Not only because they've been created by the RC itself, but also because
they are part of the release artifacts.

Stefan

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to