Skip to content

CycloneDX 2.0 #631

Description

@stevespringett

CycloneDX 2.0 is a major version in active development, focused on cleaning up legacy constructs, enforcing semantic correctness, and enabling modern schema reuse and API integration. This issue tracks the scope, rationale, and technical direction of the 2.0 release.

Goals

  • Modularize the specification into multiple schemas (e.g. bom, component, metadata, common, etc)
  • Remove deprecated fields and legacy aliases
  • Constrain properties to their correct types (e.g. cryptoProperties only on cryptographic assets)
  • JSON-first focus supporting JSON Schema Draft 2020-12; potentially remove XML support
  • Make the schema directly usable as a canonical model for the Ecma Transparency Exchange API
  • Normalize naming and structural inconsistencies

Activity

  1. added this to the 2.0 milestone on May 3, 2025
  2. jkowalleck commented on May 5, 2025

    @jkowalleck
    Member
    • Adopt JSON Schema Draft 2020-12 and drop official XML support

    same for protobuf support?

  3. pinned this issue on May 5, 2025
  4. stevespringett commented on May 6, 2025

    @stevespringett
    MemberAuthor

    same for protobuf support?

    There are so many systems that use protobuf for machine-to-machine communication, that I'd like to offer official support for it, but do so in a way where we can generate the .proto from the JSON Schema at release time. I already have a partially working Python script that does this and keeps track of enum order so that we can preserve enum ordering from release to release.

  5. jkowalleck commented on May 6, 2025

    @jkowalleck
    Member

    this is confusing to me.

    the ticket says it will drop support for anything that is not JSON, esecially XML.
    but then it says it will also provide an (autogenerated) XML schema.
    and it does not say anything about ProtoBuf.

    please improve the ticket, and make clear what is to be expected.
    will there be any XSD? will there be any ProtoBuf Schema?

  6. stevespringett commented on May 6, 2025

    @stevespringett
    MemberAuthor

    please improve the ticket,

    This ticket is essentially the "epic". Details will be provided in individual subtickets (the stories). There is too much detail to put into one ticket.

  7. linked a pull request that will close this issue[WIP] CycloneDX v2.0 Specification #652on Jun 15, 2025
  8. stevespringett commented on Dec 4, 2025

    @stevespringett
    MemberAuthor

    For those following this ticket, here's an update:

    • The entirety of CycloneDX v1.7 has been modularized into individual models. There will likely be a few more changes to the models and perhaps a few new ones to promote reuse.
    • All CycloneDX v1.7 unit tests (JSON only) have been ported to v2.0 and all pass validation.
    • The automatic bundling works as designed and is triggered on CI.
    • All deprecated properties have been removed.
    • A new linter has been created that has a lot of checks. More work to do on that front.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions