Added first-class hardware support - #982
Merged
Merged
Conversation
Signed-off-by: Steve Springett <steve@springett.us>
Signed-off-by: Pavel Shukhman <taleodor@gmail.com>
Based on HBOM group meeting from 2026-07-07. Signed-off-by: Pavel Shukhman <pavel@reliza.io>
Signed-off-by: Pavel Shukhman <pavel@reliza.io>
This PR adds origin notion to track regional provenance of hardware
components. Origin can be placed on a component level or a party level.
Proposed shape:
```
"origin": {
"basis": "number of parts",
"origins": [ { "originCode": "CA", "percentage": 0.7 } ]
}
```
…dware feature working group. Signed-off-by: Steve Springett <steve@springett.us>
Adds first-class support for raw and processed materials and for stage-specific origin declarations, such as distinguishing where a material was mined from, where it was melted, and by whom. Signed-off-by: Steve Springett <steve@springett.us>
Member
|
RFC notice sent on July 22, 2026
Public RFC period ends August 19, 2026 |
jkowalleck
requested review from
DarthHater,
coderpatros,
jkowalleck and
mrutkows
July 22, 2026 16:45
Signed-off-by: Steve Springett <steve@springett.us>
Signed-off-by: Steve Springett <steve@springett.us>
This was referenced Aug 15, 2026
Signed-off-by: Steve Springett <steve@springett.us>
Member
|
changing this was a good decision. 👍 |
jkowalleck
requested changes
Aug 20, 2026
Co-authored-by: Jan Kowalleck <jan.kowalleck@owasp.org> Signed-off-by: Steve Springett <steve@springett.us>
Co-authored-by: Jan Kowalleck <jan.kowalleck@owasp.org> Signed-off-by: Steve Springett <steve@springett.us>
jkowalleck
self-requested a review
August 20, 2026 14:20
jkowalleck
approved these changes
Aug 20, 2026
jkowalleck
reviewed
Aug 20, 2026
| "title": "Percentage", | ||
| "description": "The percentage of the whole attributable to this region. The percentages of all entries in a distribution must total 100, within rounding of the stated precision.", | ||
| "minimum": 0, | ||
| "maximum": 100 |
Member
There was a problem hiding this comment.
in other parts of CycloneDX, we go with a value from 0 to 1 to represent percentage.
- for example with "certainty"...
maybe we shoudl to this here, too?
Suggested change
| "maximum": 100 | |
| "maximum": 1 |
we then need to change the description
jkowalleck
reviewed
Aug 20, 2026
| "percentage": { | ||
| "type": "number", | ||
| "title": "Percentage", | ||
| "description": "The percentage of the whole attributable to this region. The percentages of all entries in a distribution must total 100, within rounding of the stated precision.", |
Member
There was a problem hiding this comment.
thougtsL
adding up to some full value might be funny ...
i mean, 1/3 + 2/3 = 1
so this would be 33.333333333....
and 66.666666666666....
which might not add up to the full 100 per programming language.
Signed-off-by: Steve Springett <steve@springett.us>
Signed-off-by: Steve Springett <steve@springett.us>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #981