OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

csaf-comment message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [csaf-comment] SWID reference. Consider CoSWID


Dear Mr Athias,

thank you for your feedback. Please find the answers below:

IMHO the comment is addressed by the standard:
> SWID is mentioned once
> I suggest adding reference to ISO/IEC 19770

CSAF already has an informative reference to [ISO19770-2].

> Also consider CoSWID
> See https://csrc.nist.gov/projects/software-identification-swid/guidelines

CSAF uses the x_generic_uris to support no yet explicitly mention standards. This includes CoSWID (which is, if I understood it correctly, just a different representation of SWID).

Kind regards,
p.p. Thomas Schmidt

-- 
Thomas Schmidt

From: csaf-comment@lists.oasis-open.org <csaf-comment@lists.oasis-open.org> On Behalf Of Jerome Athias
Sent: Wednesday, September 14, 2022 11:14 AM
To: csaf-comment@lists.oasis-open.org
Subject: [csaf-comment] SWID reference. Consider CoSWID

Hi

SWID is mentioned once
I suggest adding reference toÂISO/IEC 19770

Also consider CoSWID
SeeÂhttps://csrc.nist.gov/projects/software-identification-swid/guidelines

Thanks


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]