-
Notifications
You must be signed in to change notification settings - Fork 5
Open
Description
Reading about Packages and relationships, I understand how those are connected.
However, I don't really get the idea on how those would be connected when present in different SBOMs. Which would be case with Shallow SBOMs.
There's a note about this in Component-Level vs Product-Level:
Note that the root package described by the component-level SBOM, the OpenSSL Source RPM (SRPM), is the only reference present in the product-level SBOM to not duplicate information between the two SBOMs. The purl reference from the SRPM package can be used to discover the component-level SBOM from the product-level SBOM.
I'd expect some more detail in the later sections and also some examples.
Metadata
Metadata
Assignees
Labels
No labels