You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There were no technical differences; V2.2.1 is V2.2 reformatted for submission to ISO via the PAS process. As a result, new clauses were added causing the previous clause-numbering sequence to change. Also, Annexes went from having Roman numbers to Latin letters. Here is the translation between numbering in V2.2.1 and the version that came before it:
What are need for SPDX 2.2.1 support?
SBOM generation side: as there's no technical difference between SPDX 2.2 and SPDX 2.2.1, it is very likely that SBOM Tool can generate the same SBOM (2.2) and merely change "spdxVersion" to "SPDX-2.2.1" to support SPDX 2.2.1. Also changing relevant IRIs.
Validation: schema and RDF IRIs for validation may need to be updated? For SPDX 2.2.1.
The text was updated successfully, but these errors were encountered:
bact
changed the title
Support German BSI TR-03183 2.0.0 by supporting SPDX 2.2.1
Support German BSI TR-03183 2.0.0 by supporting SPDX 2.2.1 or higher
Oct 29, 2024
Background
SBOM Tool currently only supports SPDX 2.2.
New version (2.0.0) of Germany BSI TR-03183 Part 2 SBOM guideline is just released on 20 Sep 2024.
BSI TR-03183 Version 1.1 required SPDX 2.3 or higher.
BSI TR-03183 Version 2.0.0 is now required SPDX 2.2.1 or higher (page 9):
SPDX 2.2.1 is the one that is ISO standard: https://www.iso.org/standard/81870.html
There's no technical differences between V2.2 and V2.2.1, according to SPDX's Differences between V2.2.1 and V2.2 documentation.
What are need for SPDX 2.2.1 support?
The text was updated successfully, but these errors were encountered: