Skip to content

ASVS CycloneDX Export is Invalid #3354

@stevespringett

Description

@stevespringett

The current CycloneDX export is invalid and does not validate against the spec.

Specifically, the spec requires that the standards array be in the definitions property. The current ASVS export puts them in the declarations property, which is specific to attestations, not standards.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions