Hi all,

One of the suggestions in today’s call for the OpenChain Telco SIG, where we’re 
discussing proposals for an SBOM standard for the Telecommunications industry, 
was:

> SBOMs conforming to the Telco SBOM Specification need to contain the 
> information when the SBOM was created in the “Created” SPDX field and at what 
> phase of the software build it was created (“pre-build”, “build-time” or 
> “post-build”) in the CreatorComment SPDX field.

(See https://github.com/OpenChain-Project/Telco-WG/pull/15)

I raised a concern about ambiguity here, in that your application may be built 
from libraries that are built at an earlier stage, so the SBOM information may 
be created after some components are built, but before others. A recipient of 
the SBOM might also interpret each of these three phrases differently from the 
creator of the SBOM. I recall hearing that there have been conversations about 
many different SBOMs according to phase (source SBOM, build SBOM, deploy SBOM, 
cloud SBOM, etc.), so I wondered whether there was advice that the Telco SIG 
could lean upon, rather than trying to formulate a solution when it’s already a 
solved problem.

Apologies if this isn’t the right group.

steve



-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#1601): https://lists.spdx.org/g/spdx/message/1601
Mute This Topic: https://lists.spdx.org/mt/95379372/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/spdx/leave/2655439/21656/1698928721/xyzzy 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to