Skip to content

Explain why we recommend PURL and SPDX Download Location #63

Description

@MarkLodato

Right now the docs simply recommend PURL and SPDX Download Location without explaining why. We have had a question for the rationale behind this suggestion.

Draft:

  • SPDX Download Location covers version control systems. There is no standard way to reference a git repo via a URI (and identify that it is git). SPDX Download Location is one of the most popular way of doing so, so we chose that.
  • PURL covers most packaging ecosystems. If one is missing, you can add it. It is really the only universal option. I haven't found any other scheme that does this.
  • Both SPDX and PURL are used extensively within the SBOM ecosystem, which fits nicely with attestations and SLSA.
  • Regular https can be used when it's literally just fetching a file with a GET request.

You can use a different URI scheme if needed. For example, within Google we'll use some internal URIs for systems that are not public. But on the internet, I suspect PURL and SPDX will cover most cases.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions