[WIP] CycloneDX v2.0 Specification - #652
stevespringett wants to merge 378 commits into
Conversation
| // Pattern for markdown links at the end | ||
| const markdownLinkPattern = /\]\([^)]+\)$/; | ||
|
|
||
| return urlPattern.test(text) || markdownLinkPattern.test(text); |
Check failure
Code scanning / CodeQL
Polynomial regular expression used on uncontrolled data High
| // Pattern for markdown links at the end | ||
| const markdownLinkPattern = /\]\([^)]+\)$/; | ||
|
|
||
| return urlPattern.test(text) || markdownLinkPattern.test(text); |
Check failure
Code scanning / CodeQL
Polynomial regular expression used on uncontrolled data High
| const absoluteRootPath = path.resolve(rootSchemaPath); | ||
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 8 minutes ago
General fix: validate user-controlled path inputs against a strict policy before using them in filesystem APIs. For this script, the least disruptive and most practical policy is: only allow paths that resolve under the current working directory (project workspace), and reject anything outside it.
Best fix in this file:
- Add a helper that resolves a user input path against
process.cwd(), then verifies the resolved path is inside that base directory (or equal to it). - Use that helper for both
modelsDirectoryandrootSchemaPathin the CLI block before callingbundleSchemas. - Keep
bundleSchemasbehavior unchanged; only sanitize/validate at the trust boundary (CLI parsing). - Reuse existing
isInsideDirhelper to avoid unnecessary new dependencies.
Edits are only in tools/src/main/js/bundler/bundle-schemas.js:
- Add
resolveCliPathWithinCwd(...)helper afterisInsideDir. - In CLI section, resolve and validate both args, handle invalid input with a clear error +
process.exit(1). - Pass validated absolute paths to
bundleSchemas.
| @@ -16,6 +16,18 @@ | ||
| } | ||
|
|
||
| /** | ||
| * Resolve a CLI-provided path and ensure it stays within the current working directory. | ||
| */ | ||
| function resolveCliPathWithinCwd(inputPath, label) { | ||
| const cwd = path.resolve(process.cwd()); | ||
| const resolved = path.resolve(cwd, inputPath); | ||
| if (resolved !== cwd && !isInsideDir(resolved, cwd)) { | ||
| throw new Error(`${label} must be within the current working directory: ${cwd}`); | ||
| } | ||
| return resolved; | ||
| } | ||
|
|
||
| /** | ||
| * Whether `ref` is an absolute URI (has a scheme, e.g. `https://...`, `urn:`). | ||
| * Such refs always point to external schemas: they are never bundled, rewritten nor checked. | ||
| */ | ||
| @@ -432,7 +444,17 @@ | ||
| process.exit(1); | ||
| } | ||
|
|
||
| bundleSchemas(modelsDirectory, rootSchemaPath, {validate: true}) | ||
| let safeModelsDirectory; | ||
| let safeRootSchemaPath; | ||
| try { | ||
| safeModelsDirectory = resolveCliPathWithinCwd(modelsDirectory, 'modelsDirectory'); | ||
| safeRootSchemaPath = resolveCliPathWithinCwd(rootSchemaPath, 'rootSchemaPath'); | ||
| } catch (err) { | ||
| console.error(`Invalid path argument: ${err.message}`); | ||
| process.exit(1); | ||
| } | ||
|
|
||
| bundleSchemas(safeModelsDirectory, safeRootSchemaPath, {validate: true}) | ||
| .catch(err => { | ||
| console.error(err); | ||
| process.exit(1); |
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); | ||
| await fs.access(absoluteRootPath); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 7 minutes ago
The best fix is to validate and constrain rootSchemaPath to a safe root before using it in filesystem operations. In this file, the natural safe root is modelsDirectory (already resolved as absoluteModelsDir). Keep existing behavior as much as possible by:
- Resolving both paths to absolute normalized paths.
- Verifying
absoluteRootPathis equal to or insideabsoluteModelsDir. - Failing fast with a clear error if it is outside.
Concretely in tools/src/main/js/bundler/bundle-schemas.js:
- Add a helper that allows “inside-or-equal” directory checks (current
isInsideDirrejects equality). - In
bundleSchemas, right after resolvingabsoluteModelsDir/absoluteRootPathand beforefs.access, enforce that root schema is contained within models directory. - Throw an error when invalid. This preserves core functionality (bundling schemas from provided model directory) while preventing path traversal / arbitrary file access via CLI input.
| @@ -16,6 +16,14 @@ | ||
| } | ||
|
|
||
| /** | ||
| * Whether `filePath` is equal to `dirPath` or lives inside it. Both must be absolute. | ||
| */ | ||
| function isInsideOrEqualDir(filePath, dirPath) { | ||
| const rel = path.relative(dirPath, filePath); | ||
| return rel === '' || (!rel.startsWith('..') && !path.isAbsolute(rel)); | ||
| } | ||
|
|
||
| /** | ||
| * Whether `ref` is an absolute URI (has a scheme, e.g. `https://...`, `urn:`). | ||
| * Such refs always point to external schemas: they are never bundled, rewritten nor checked. | ||
| */ | ||
| @@ -196,6 +204,13 @@ | ||
| const absoluteModelsDir = path.resolve(modelsDirectory); | ||
| const absoluteRootPath = path.resolve(rootSchemaPath); | ||
|
|
||
| // Ensure the root schema path is constrained to the models directory. | ||
| if (!isInsideOrEqualDir(absoluteRootPath, absoluteModelsDir)) { | ||
| throw new Error( | ||
| `Root schema path must be inside models directory. rootSchemaPath=${absoluteRootPath}, modelsDirectory=${absoluteModelsDir}` | ||
| ); | ||
| } | ||
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); | ||
| await fs.access(absoluteRootPath); |
| console.log(`Output (minified): ${minifiedPath}\n`); | ||
|
|
||
| // Read all schema files in the models directory | ||
| const files = await fs.readdir(absoluteModelsDir); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 7 minutes ago
To fix this safely without changing core functionality, validate that both CLI-provided paths stay within an expected safe base directory (the current working directory is a practical default for this script). Keep normalization via path.resolve, then enforce containment with the existing isInsideDir helper (plus equality check to allow the base dir itself). Reject paths outside the safe root before any filesystem access.
Best concrete fix in this file:
- In
bundleSchemas(around lines 196–202), after resolvingabsoluteModelsDir/absoluteRootPath, computesafeRootDir = path.resolve(process.cwd()). - Check both resolved paths are either equal to
safeRootDiror inside it. - Throw an error if validation fails.
- This introduces no new dependencies/imports and uses existing helper logic.
| @@ -195,7 +195,15 @@ | ||
| try { | ||
| const absoluteModelsDir = path.resolve(modelsDirectory); | ||
| const absoluteRootPath = path.resolve(rootSchemaPath); | ||
| const safeRootDir = path.resolve(process.cwd()); | ||
|
|
||
| // Validate user-provided paths stay within the allowed workspace root | ||
| const modelsDirAllowed = absoluteModelsDir === safeRootDir || isInsideDir(absoluteModelsDir, safeRootDir); | ||
| const rootSchemaAllowed = absoluteRootPath === safeRootDir || isInsideDir(absoluteRootPath, safeRootDir); | ||
| if (!modelsDirAllowed || !rootSchemaAllowed) { | ||
| throw new Error(`Input paths must be within the current working directory: ${safeRootDir}`); | ||
| } | ||
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); | ||
| await fs.access(absoluteRootPath); |
| const schemaPath = path.join(absoluteModelsDir, file); | ||
| console.log(` Reading ${file}...`); | ||
|
|
||
| const content = await fs.readFile(schemaPath, 'utf8'); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 8 minutes ago
To fix this without changing intended functionality, validate that both user-provided paths are inside an expected safe root (the current working directory), after normalization. Then, when constructing per-file paths from readdir, resolve and re-check each candidate path stays within the validated models directory before reading.
Best concrete fix in tools/src/main/js/bundler/bundle-schemas.js:
- Add a helper that normalizes and validates a user path against a base directory (using
path.resolve+isInsideDir/ equality check). - In
bundleSchemas, derivesafeRootDir = path.resolve(process.cwd()). - Replace direct
path.resolve(modelsDirectory/rootSchemaPath)with validated absolute paths from the helper. - In the schema loop, use
path.resolve(absoluteModelsDir, file)and skip anything that escapesabsoluteModelsDir(defense in depth). - Keep behavior otherwise unchanged.
No new dependencies are required.
| @@ -15,6 +15,14 @@ | ||
| return rel !== '' && !rel.startsWith('..') && !path.isAbsolute(rel); | ||
| } | ||
|
|
||
| function resolveAndValidateInsideBase(userPath, baseDir, label) { | ||
| const absolutePath = path.resolve(userPath); | ||
| if (absolutePath !== baseDir && !isInsideDir(absolutePath, baseDir)) { | ||
| throw new Error(`${label} must be inside ${baseDir}: ${userPath}`); | ||
| } | ||
| return absolutePath; | ||
| } | ||
|
|
||
| /** | ||
| * Whether `ref` is an absolute URI (has a scheme, e.g. `https://...`, `urn:`). | ||
| * Such refs always point to external schemas: they are never bundled, rewritten nor checked. | ||
| @@ -193,8 +201,9 @@ | ||
|
|
||
| async function bundleSchemas(modelsDirectory, rootSchemaPath, options = {}) { | ||
| try { | ||
| const absoluteModelsDir = path.resolve(modelsDirectory); | ||
| const absoluteRootPath = path.resolve(rootSchemaPath); | ||
| const safeRootDir = path.resolve(process.cwd()); | ||
| const absoluteModelsDir = resolveAndValidateInsideBase(modelsDirectory, safeRootDir, 'modelsDirectory'); | ||
| const absoluteRootPath = resolveAndValidateInsideBase(rootSchemaPath, safeRootDir, 'rootSchemaPath'); | ||
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); | ||
| @@ -228,7 +237,11 @@ | ||
| let detectedSchemaVersion = null; | ||
|
|
||
| for (const file of schemaFiles) { | ||
| const schemaPath = path.join(absoluteModelsDir, file); | ||
| const schemaPath = path.resolve(absoluteModelsDir, file); | ||
| if (schemaPath !== absoluteModelsDir && !isInsideDir(schemaPath, absoluteModelsDir)) { | ||
| console.warn(` Skipping path outside models directory: ${file}`); | ||
| continue; | ||
| } | ||
| console.log(` Reading ${file}...`); | ||
|
|
||
| const content = await fs.readFile(schemaPath, 'utf8'); |
|
|
||
| // Read the root schema | ||
| console.log(`\nReading root schema...`); | ||
| const rootContent = await fs.readFile(absoluteRootPath, 'utf8'); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 8 minutes ago
Best fix: enforce a safe root directory boundary for both modelsDirectory and rootSchemaPath before any filesystem read/list operations. General approach: canonicalize candidate paths and root path, then verify candidate is inside root; reject otherwise.
In tools/src/main/js/bundler/bundle-schemas.js:
- Add a helper that resolves symlinks/canonical paths via
fs.realpathand checks containment with existingisInsideDir(plus equality allowance where appropriate). - In
bundleSchemas, after resolving input paths and beforefs.access/readFile/readdir, compute a trusted base (here:process.cwd()), canonicalize it, and validate:absoluteModelsDirmust be inside base dir.absoluteRootPathmust be inside base dir.
- Throw an explicit error when validation fails.
This preserves existing functionality for normal project-relative usage while blocking traversal to unexpected filesystem locations.
| // Write bundled (pretty) version | ||
| console.log('\nWriting bundled schema...'); | ||
| const prettyJson = JSON.stringify(finalSchema, null, 2); | ||
| await fs.writeFile(bundledPath, prettyJson); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 8 minutes ago
To fix this without changing intended functionality, validate that rootSchemaPath is inside the provided modelsDirectory before deriving output paths and writing files. In general, when user input influences filesystem paths, resolve both paths to absolute canonical form and enforce a containment rule (safe root directory).
Best fix in this file:
- In
bundleSchemas(...), after resolving/access checks and before usingrootSchemaDir/bundledPath, add a guard:- Ensure
absoluteRootPathis equal toabsoluteModelsDiror is inside it (isInsideDir(absoluteRootPath, absoluteModelsDir)). - If not, throw an error.
- Ensure
- This reuses the existing
isInsideDirhelper and preserves existing behavior for valid invocations while preventing writes outside the models tree.
No new imports or dependencies are required.
| @@ -200,6 +200,11 @@ | ||
| await fs.access(absoluteModelsDir); | ||
| await fs.access(absoluteRootPath); | ||
|
|
||
| // Ensure root schema path is constrained to the models directory | ||
| if (absoluteRootPath !== absoluteModelsDir && !isInsideDir(absoluteRootPath, absoluteModelsDir)) { | ||
| throw new Error(`Root schema path must be inside models directory: ${absoluteRootPath}`); | ||
| } | ||
|
|
||
| const rootSchemaFilename = path.basename(absoluteRootPath); | ||
| const rootSchemaDir = path.dirname(absoluteRootPath); | ||
|
|
| console.log('\nWriting bundled schema...'); | ||
| const prettyJson = JSON.stringify(finalSchema, null, 2); | ||
| await fs.writeFile(bundledPath, prettyJson); | ||
| const bundledStats = await fs.stat(bundledPath); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 8 minutes ago
To fix this safely without changing intended behavior, validate that both user-provided paths are constrained to an expected safe root (the current working directory), after canonicalization. Specifically:
- In
bundleSchemas, computesafeRoot = await fs.realpath(process.cwd()). - Canonicalize user inputs:
absoluteModelsDir = await fs.realpath(path.resolve(modelsDirectory))absoluteRootPath = await fs.realpath(path.resolve(rootSchemaPath))
- Enforce containment with the existing
isInsideDirhelper (plus equality check):- allow when
candidate === safeRoot || isInsideDir(candidate, safeRoot) - reject otherwise with an error.
- allow when
- Keep existing functionality (same outputs relative to provided schema path) for valid in-repo paths.
This requires edits only in tools/src/main/js/bundler/bundle-schemas.js, inside bundleSchemas near lines 196–201.
| @@ -193,9 +193,16 @@ | ||
|
|
||
| async function bundleSchemas(modelsDirectory, rootSchemaPath, options = {}) { | ||
| try { | ||
| const absoluteModelsDir = path.resolve(modelsDirectory); | ||
| const absoluteRootPath = path.resolve(rootSchemaPath); | ||
| const safeRoot = await fs.realpath(process.cwd()); | ||
| const absoluteModelsDir = await fs.realpath(path.resolve(modelsDirectory)); | ||
| const absoluteRootPath = await fs.realpath(path.resolve(rootSchemaPath)); | ||
|
|
||
| const modelsDirAllowed = absoluteModelsDir === safeRoot || isInsideDir(absoluteModelsDir, safeRoot); | ||
| const rootSchemaAllowed = absoluteRootPath === safeRoot || isInsideDir(absoluteRootPath, safeRoot); | ||
| if (!modelsDirAllowed || !rootSchemaAllowed) { | ||
| throw new Error(`Input paths must be inside the working directory: ${safeRoot}`); | ||
| } | ||
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); | ||
| await fs.access(absoluteRootPath); |
| const lineCount = minifiedJson.split('\n').length; | ||
| console.log(` Minified JSON is on ${lineCount} line(s)`); | ||
|
|
||
| await fs.writeFile(minifiedPath, minifiedJson); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 8 minutes ago
The safest fix without changing intended functionality is to enforce that both the input root schema and generated output files remain inside the provided models directory after canonicalization. This keeps current behavior (write beside root schema) for valid inputs, while blocking dangerous paths.
In tools/src/main/js/bundler/bundle-schemas.js, inside bundleSchemas:
- Canonicalize
modelsDirectoryandrootSchemaPathwithfs.realpath(...)afterpath.resolve(...). - Validate
absoluteRootPathis insideabsoluteModelsDir(or equal to it if desired policy; here we require “inside” as existing helper does). - Build output paths as today, then canonicalize their parent dirs (
fs.realpath(path.dirname(...))) and reconstruct canonical target paths. - Validate canonical output targets are inside canonical models dir before writing.
- Throw explicit errors when checks fail.
No new dependency is required; existing path, fs.promises, and existing isInsideDir helper are sufficient.
| @@ -193,13 +193,22 @@ | ||
|
|
||
| async function bundleSchemas(modelsDirectory, rootSchemaPath, options = {}) { | ||
| try { | ||
| const absoluteModelsDir = path.resolve(modelsDirectory); | ||
| const absoluteRootPath = path.resolve(rootSchemaPath); | ||
| const resolvedModelsDir = path.resolve(modelsDirectory); | ||
| const resolvedRootPath = path.resolve(rootSchemaPath); | ||
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); | ||
| await fs.access(absoluteRootPath); | ||
| await fs.access(resolvedModelsDir); | ||
| await fs.access(resolvedRootPath); | ||
|
|
||
| // Canonicalize paths to prevent traversal/symlink escapes | ||
| const absoluteModelsDir = await fs.realpath(resolvedModelsDir); | ||
| const absoluteRootPath = await fs.realpath(resolvedRootPath); | ||
|
|
||
| // Root schema must be inside the trusted models directory | ||
| if (!isInsideDir(absoluteRootPath, absoluteModelsDir)) { | ||
| throw new Error(`Root schema must be inside models directory: ${absoluteModelsDir}`); | ||
| } | ||
|
|
||
| const rootSchemaFilename = path.basename(absoluteRootPath); | ||
| const rootSchemaDir = path.dirname(absoluteRootPath); | ||
|
|
||
| @@ -211,9 +217,19 @@ | ||
| const bundledFilename = `${baseFilename}-bundled.schema.json`; | ||
| const minifiedFilename = `${baseFilename}-bundled.min.schema.json`; | ||
|
|
||
| const bundledPath = path.join(rootSchemaDir, bundledFilename); | ||
| const minifiedPath = path.join(rootSchemaDir, minifiedFilename); | ||
| const bundledPathCandidate = path.join(rootSchemaDir, bundledFilename); | ||
| const minifiedPathCandidate = path.join(rootSchemaDir, minifiedFilename); | ||
|
|
||
| // Canonicalize target directories and enforce output containment | ||
| const bundledDirCanonical = await fs.realpath(path.dirname(bundledPathCandidate)); | ||
| const minifiedDirCanonical = await fs.realpath(path.dirname(minifiedPathCandidate)); | ||
| const bundledPath = path.join(bundledDirCanonical, path.basename(bundledPathCandidate)); | ||
| const minifiedPath = path.join(minifiedDirCanonical, path.basename(minifiedPathCandidate)); | ||
|
|
||
| if (!isInsideDir(bundledPath, absoluteModelsDir) || !isInsideDir(minifiedPath, absoluteModelsDir)) { | ||
| throw new Error(`Output paths must be inside models directory: ${absoluteModelsDir}`); | ||
| } | ||
|
|
||
| console.log(`Output (bundled): ${bundledPath}`); | ||
| console.log(`Output (minified): ${minifiedPath}\n`); | ||
|
|
| console.log(` Minified JSON is on ${lineCount} line(s)`); | ||
|
|
||
| await fs.writeFile(minifiedPath, minifiedJson); | ||
| const minifiedStats = await fs.stat(minifiedPath); |
Check failure
Code scanning / CodeQL
Uncontrolled data used in path expression High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 8 minutes ago
The safest fix without changing intended functionality is to enforce that both input paths stay within an approved base directory (current working directory is a practical default), and to validate output paths as well before writing.
In tools/src/main/js/bundler/bundle-schemas.js:
- Add a helper to safely resolve a candidate path under a base directory and reject escapes.
- In
bundleSchemas, resolvemodelsDirectoryandrootSchemaPathvia that helper instead of rawpath.resolve(...). - After constructing
bundledPathandminifiedPath, verify both remain inside the same safe base before any write/stat operations. - Keep behavior intact for normal valid project-local usage; only reject traversal/outside-base paths with a clear error.
No new dependency is required; existing path utilities and the existing isInsideDir helper are sufficient.
| @@ -15,6 +15,15 @@ | ||
| return rel !== '' && !rel.startsWith('..') && !path.isAbsolute(rel); | ||
| } | ||
|
|
||
| function resolvePathWithinBase(baseDir, inputPath, argumentName) { | ||
| const resolvedBase = path.resolve(baseDir); | ||
| const resolvedPath = path.resolve(resolvedBase, inputPath); | ||
| if (resolvedPath !== resolvedBase && !isInsideDir(resolvedPath, resolvedBase)) { | ||
| throw new Error(`${argumentName} must be within ${resolvedBase}`); | ||
| } | ||
| return resolvedPath; | ||
| } | ||
|
|
||
| /** | ||
| * Whether `ref` is an absolute URI (has a scheme, e.g. `https://...`, `urn:`). | ||
| * Such refs always point to external schemas: they are never bundled, rewritten nor checked. | ||
| @@ -193,8 +202,9 @@ | ||
|
|
||
| async function bundleSchemas(modelsDirectory, rootSchemaPath, options = {}) { | ||
| try { | ||
| const absoluteModelsDir = path.resolve(modelsDirectory); | ||
| const absoluteRootPath = path.resolve(rootSchemaPath); | ||
| const safeBaseDir = path.resolve(process.cwd()); | ||
| const absoluteModelsDir = resolvePathWithinBase(safeBaseDir, modelsDirectory, 'modelsDirectory'); | ||
| const absoluteRootPath = resolvePathWithinBase(safeBaseDir, rootSchemaPath, 'rootSchemaPath'); | ||
|
|
||
| // Verify paths exist | ||
| await fs.access(absoluteModelsDir); | ||
| @@ -214,6 +224,13 @@ | ||
| const bundledPath = path.join(rootSchemaDir, bundledFilename); | ||
| const minifiedPath = path.join(rootSchemaDir, minifiedFilename); | ||
|
|
||
| if (bundledPath !== safeBaseDir && !isInsideDir(bundledPath, safeBaseDir)) { | ||
| throw new Error(`Refusing to write bundled schema outside ${safeBaseDir}`); | ||
| } | ||
| if (minifiedPath !== safeBaseDir && !isInsideDir(minifiedPath, safeBaseDir)) { | ||
| throw new Error(`Refusing to write minified schema outside ${safeBaseDir}`); | ||
| } | ||
|
|
||
| console.log(`Output (bundled): ${bundledPath}`); | ||
| console.log(`Output (minified): ${minifiedPath}\n`); | ||
|
|
f63bd4a to
9a09935
Compare
Signed-off-by: Steve Springett <steve@springett.us>
…-dev-threatmodeling
Signed-off-by: Steve Springett <steve@springett.us>
Signed-off-by: Steve Springett <steve@springett.us>
Signed-off-by: Jan Kowalleck <jan.kowalleck@owasp.org>
Signed-off-by: Basil Hess <bhe@zurich.ibm.com>
…the various models. Signed-off-by: Steve Springett <steve@springett.us>
Signed-off-by: Steve Springett <steve@springett.us>
Signed-off-by: Steve Springett <steve@springett.us>
selectedBy now only names the mechanism: protocol-fixed, build-time, configuration, negotiation, or unknown. The new optional selectingParty names who selects (client, server, initiator, responder, ...), which also covers multi-party protocols. server-selected and hardware are dropped. Also documents the registry join (exact match on family and version) and the algorithm name resolution rule. Signed-off-by: Basil Hess <bhe@zurich.ibm.com>
protocolProperties.type plus version identify the registry entry by exact match. Adds a valid and an invalid test case for the protocol type. Signed-off-by: Basil Hess <bhe@zurich.ibm.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Basil Hess <bhe@zurich.ibm.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
# Conflicts: # schema/2.0/model/cyclonedx-cryptography-2.0.schema.json
- End all protocolFamiliesEnum meta:enum descriptions with a full stop - Drop the redundant "type" keyword from enums in cryptography-defs, in line with the const/enum refactor on 2.0-dev - Add the missing newline at end of cryptography-defs.schema.json - Rename the protocolProperties.type title to "Protocol Type"
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Important
WORK IN PROGRESS
see Milestone for progress: https://github.com/CycloneDX/specification/milestone/2
BREAKING Changes
To be explained further.
Reasoning: Downstream spec users may build ontop of JSON schema.
To be explained further.
... TBC ...
Added
... TBD ...
Chaned
... TBD ...
Removed
... TBD ...
Misc
... TBD ...