- Replace fabricated library-binary SHA-256/SHA-1 with all-zeros sentinels in the pinned wolfssl-component samples (cdx/spdx + commercial variants); a non-reproducible binary hash must not ship in a copyable sample. - Recompute product bom-link checksums (CycloneDX bom hash + SPDX externalDocumentRef) to match the edited component SBOMs. - Give the SPDX tag-value document a distinct documentNamespace so it no longer collides with the JSON serialization (SPDX 2.3 sec 3.5). - Add licenses (GPL-3.0-only) to the wolfssl component in the product CDX (NTIA minimum elements). - Align conformity-assessment-route.md wording to Annex III "important" / Annex IV "critical", dropping the "class II" label. - Document the sentinel digest in SAMPLE-PROVENANCE.md. validate.sh passes (cross-document checksums + pyspdxtools schema). Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> |
||
|---|---|---|
| .. | ||
| README-bomsh.md | ||
| SAMPLE-PROVENANCE.md | ||
| omnibor.wolfssl-5.9.1.spdx.json.sample | ||
| wolfssl-5.9.1.cbom-draft.cdx.json | ||
| wolfssl-5.9.1.cdx.json | ||
| wolfssl-5.9.1.commercial.cdx.json | ||
| wolfssl-5.9.1.commercial.spdx.json | ||
| wolfssl-5.9.1.spdx | ||
| wolfssl-5.9.1.spdx.json | ||