Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS] Document your CycloneDX properties #2316

Open
jkowalleck opened this issue Dec 11, 2024 · 1 comment
Open

[DOCS] Document your CycloneDX properties #2316

jkowalleck opened this issue Dec 11, 2024 · 1 comment
Labels
documentation Improvements or additions to documentation enhancement New feature or request

Comments

@jkowalleck
Copy link

What would you like to be added:

Their is a registered/reserved CycloneDX Property Taxonomy Top-Level Namespace grype. https://github.com/CycloneDX/cyclonedx-property-taxonomy/blob/ed8a972a5e1c925bba05f8865c1ad3219b872c98/README.md?plain=1#L99C4-L99C9

I would love to see a documentation of the CycloneDX property taxonomy used by grype.
Maybe I just missed it?

Why is this needed:

If grype used custom CycloneDX properties, it would help to know then, and understand when they should be used and what they mean.

Additional context:

I am not certain whether the TL-Namespace grype is used at all.
Ifnot, it might even help to publish an "empty" docs space like so https://github.com/DependencyTrack/cyclonedx-property-taxonomy

@willmurphyscode
Copy link
Contributor

Adding this to ready. What we should do next:

  1. Look at exactly what what fields Syft and Grype output
  2. PR to the CycloneDX docs, making a file called syft.md and grype.md as siblings of this file. (Note that Syft and Grype are doing different things, and need to be documented separately.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation enhancement New feature or request
Projects
Status: Ready
Development

No branches or pull requests

3 participants