wolfssl-examples/cra-kit/auditor-packet
Sameeh Jubran 811b31a363 cra-kit: address Atwood re-review blockers on #574
- Replace fabricated library-binary SHA-256/SHA-1 with all-zeros sentinels
  in the pinned wolfssl-component samples (cdx/spdx + commercial variants);
  a non-reproducible binary hash must not ship in a copyable sample.
- Recompute product bom-link checksums (CycloneDX bom hash + SPDX
  externalDocumentRef) to match the edited component SBOMs.
- Give the SPDX tag-value document a distinct documentNamespace so it no
  longer collides with the JSON serialization (SPDX 2.3 sec 3.5).
- Add licenses (GPL-3.0-only) to the wolfssl component in the product CDX
  (NTIA minimum elements).
- Align conformity-assessment-route.md wording to Annex III "important" /
  Annex IV "critical", dropping the "class II" label.
- Document the sentinel digest in SAMPLE-PROVENANCE.md.

validate.sh passes (cross-document checksums + pyspdxtools schema).

Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
2026-07-02 17:50:01 +03:00
..
wolfssl-component cra-kit: address Atwood re-review blockers on #574 2026-07-02 17:50:01 +03:00
wolfssl-component-embedded cra-kit: address Atwood review (shell safety, validation, samples) 2026-06-17 17:27:15 +03:00
00-INDEX.md Add CRA Kit for customer SBOM integration 2026-06-04 04:54:45 +03:00
README.md cra-kit: fix commercial-license SBOM generation and refresh samples 2026-06-22 13:40:11 +03:00
product-acme-connect-gateway.cdx.json cra-kit: address Atwood re-review blockers on #574 2026-07-02 17:50:01 +03:00
product-acme-connect-gateway.spdx.json cra-kit: address Atwood re-review blockers on #574 2026-07-02 17:50:01 +03:00

README.md

Sample auditor packet

This directory is a teaching example only. Acme Industries and acme-connect-gateway are fictional.

It shows how a product SBOM references wolfSSLs component SBOM in both CycloneDX and SPDX forms.

See 00-INDEX.md for the file list.