Skip to content

Conversation

@adam-dev2
Copy link

This PR adds SPDX (ISO/IEC 5962:2021) as a reference in A03:2025 - Software Supply Chain Failures, addressing the request made in issue #857. SPDX is the other major SBOM standard alongside CycloneDX and its inclusion improves completeness and neutrality in the references.

Copy link

@swinslow swinslow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM -- thank you @adam-dev2!

@adam-dev2
Copy link
Author

Appreciated it :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants