What would you like to be added:
syft makes use of cyclonedx properties to record metadata that is not directly supported by the cyclonedx spec. We should register a syft namespace and document the syft cyclonedx property taxonomy if possible.
Why is this needed: CycloneDX supports arbitrary properties. In order to make the experience using them better, it supports taxonomies to allow various project to categorize and use property keys without namespace collision.
Additional context:
See #819 (comment)
What would you like to be added:
syft makes use of cyclonedx properties to record metadata that is not directly supported by the cyclonedx spec. We should register a syft namespace and document the syft cyclonedx property taxonomy if possible.
Why is this needed: CycloneDX supports arbitrary properties. In order to make the experience using them better, it supports taxonomies to allow various project to categorize and use property keys without namespace collision.
Additional context:
See #819 (comment)