-
-
Notifications
You must be signed in to change notification settings - Fork 68
Closed
Labels
Description
I am still uncertain which elements allow the use of bomlink.
From use cases it appears to be possible in externalReferences[].url
, vulnerabilities[].affects[].ref
.
Any where else?
I'd suggest enhancing the schema to make it visible where a bomlink is allowed and where it is not.
This helps tool builders, parsers, and most importantly clarifies this from schema, not only some additional pamphlets/texts.