Skip to content

Explain how inter SBOM linking works #74

@ctron

Description

@ctron

Reading about Packages and relationships, I understand how those are connected.

However, I don't really get the idea on how those would be connected when present in different SBOMs. Which would be case with Shallow SBOMs.

There's a note about this in Component-Level vs Product-Level:

Note that the root package described by the component-level SBOM, the OpenSSL Source RPM (SRPM), is the only reference present in the product-level SBOM to not duplicate information between the two SBOMs. The purl reference from the SRPM package can be used to discover the component-level SBOM from the product-level SBOM.

I'd expect some more detail in the later sections and also some examples.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions