-
Uncategorized
Designed to be deprecated
Every vendor namespace meets the same objection, lock-in. The Profile's answer is binding: a one-to-one mapping when the core adopts a field, enumeration translation, a two-version window, and no removal without a major increment.
Read More » -
Uncategorized
What the TLP label in CycloneDX 1.7 does, and what it does not
CycloneDX 1.7 made pass-it-on permission a field rather than an email footer, defaulting to CLEAR. What the label solves, the three things it doesn't, where CERT-In went further, and what we intend to build on all three.
Read More » -
Uncategorized
Why we used pedigree rather than inventing a field
Implementation ancestry is the hardest input the Profile asks for, and CycloneDX already had the structure for it. Chains, merges, the lineage delta, and why reusing pedigree beats inventing a field.
Read More » -
Uncategorized
A taxonomy, not a dialect
The Applied Quantum CBOM Profile is a property taxonomy layered on CycloneDX, not a competing specification. Four tiers, two consuming frameworks, one binding exit policy, and honest status on a registration in flight.
Read More »