The Model Namespace Template markdown file Sean sent out on April 27 says:

# <Namespace Name> Namespace Specification

< This is a template to be used for creating documentation for each
namespace within 3T-SBOM/SPDX model specification.  The text
immediately following the heading is a summary of the naemspace
itself.>


This is fine for defining parts of the specification.  But in the Core
specification the SBOM Document has a namespace URI that identifies the
device / application / container / service / software-distribution
described by that SBOM.  When one SBOM refers to another SBOM using an
external reference, with (or without) content validated with a signature or
hash, the referenced SBOM has a namespace URI that distinguishes it from
every other SBOM on the planet.

We should be clear that specification namespaces and SBOM Document
namespaces are different animals.

Dave


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#4073): https://lists.spdx.org/g/Spdx-tech/message/4073
Mute This Topic: https://lists.spdx.org/mt/83541869/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/Spdx-tech/unsub [[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to