Skip to content

[WIP] harmonize actors with party model - #1100

Draft
jkowalleck wants to merge 1 commit into
2.0-devfrom
2.0-dev_role-based-parties-harmoize
Draft

[WIP] harmonize actors with party model#1100
jkowalleck wants to merge 1 commit into
2.0-devfrom
2.0-dev_role-based-parties-harmoize

Conversation

@jkowalleck

@jkowalleck jkowalleck commented Sep 10, 2026

Copy link
Copy Markdown
Member

Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
@jkowalleck jkowalleck changed the title [WIP] harmonixe actors with party model [WIP] harmonize actors with party model Sep 10, 2026
taleodor-claude pushed a commit to relizaio/sbom-everywhere that referenced this pull request Sep 13, 2026
The CycloneDX 2.0 column carried "Same" for SBOM Author, inheriting
`metadata.manufacturer.name` or `authors[].name` from 1.6 and 1.7.
CycloneDX/specification#1100 replaces `metadata.authors`,
`metadata.manufacturer` and `metadata.supplier` with `metadata.parties`,
so neither field survives into 2.0 and the row now names
`metadata.parties[]`. It cites note [a], which already describes the
party shape generally: roles are the only requirement, alongside one
identity block. This also makes the metadata row symmetric with
Component Producer, which already maps to `components[].parties[]`.

Note [y] introduced the relationship as `descendentOf` and then used
`descendantOf` in the following sentence. The latter is the SPDX
relationship type, so the first spelling is corrected.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
taleodor-claude pushed a commit to relizaio/sbom-everywhere that referenced this pull request Sep 13, 2026
The CycloneDX 2.0 column carried "Same" for SBOM Author, inheriting
`metadata.manufacturer.name` or `authors[].name` from 1.6 and 1.7.
CycloneDX/specification#1100 replaces `metadata.authors`,
`metadata.manufacturer` and `metadata.supplier` with `metadata.parties`,
so neither field survives into 2.0 and the row now names
`metadata.parties[]`. It cites note [a], which already describes the
party shape generally: roles are the only requirement, alongside one
identity block. This also makes the metadata row symmetric with
Component Producer, which already maps to `components[].parties[]`.

Note [y] introduced the relationship as `descendentOf` and then used
`descendantOf` in the following sentence. The latter is the SPDX
relationship type, so the first spelling is corrected.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Claude Code (ReARM Agent) <rearm-agent-claude@reliza.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant