- Replace fabricated library-binary SHA-256/SHA-1 with all-zeros sentinels in the pinned wolfssl-component samples (cdx/spdx + commercial variants); a non-reproducible binary hash must not ship in a copyable sample. - Recompute product bom-link checksums (CycloneDX bom hash + SPDX externalDocumentRef) to match the edited component SBOMs. - Give the SPDX tag-value document a distinct documentNamespace so it no longer collides with the JSON serialization (SPDX 2.3 sec 3.5). - Add licenses (GPL-3.0-only) to the wolfssl component in the product CDX (NTIA minimum elements). - Align conformity-assessment-route.md wording to Annex III "important" / Annex IV "critical", dropping the "class II" label. - Document the sentinel digest in SAMPLE-PROVENANCE.md. validate.sh passes (cross-document checksums + pyspdxtools schema). Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> |
||
|---|---|---|
| .. | ||
| wolfssl-component | ||
| wolfssl-component-embedded | ||
| 00-INDEX.md | ||
| README.md | ||
| product-acme-connect-gateway.cdx.json | ||
| product-acme-connect-gateway.spdx.json | ||
README.md
Sample auditor packet
This directory is a teaching example only. Acme Industries and acme-connect-gateway are fictional.
It shows how a product SBOM references wolfSSL’s component SBOM in both CycloneDX and SPDX forms.
See 00-INDEX.md for the file list.