Skip to content

BSI TR-03183-2 sbom_build reported by sbomqs, but not in standard. #586

@robin-s-007

Description

@robin-s-007

Hello,

I using sbomqs to validate an SBOM template (CycloneDX v1.6 JSON) against the BSI v2.1.0 standard.
While sbomqs only supports BSI v2.0 the changelog in v2.1.0 does not list anything significant differences.

sbomqs reports a missing sbom_build feature.
However the BSI spec does not mention such a feature, I guess this comes from the SPDX meta data.
CycloneDX has something simular with the version field, but this is not interpreted as such.

Is this what is ment ?

Best Regards,

Robin

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions