Skip to content

Finding BOM v1 Schema

Validates one L2 Finding BOM version. Shape-only: ref resolution (provenanceRef/approvalRef), author-identity equality with the provenance attestation, the disclosability condition, and supersession chains are verifier (adbom-cli) checks. Normative requirements: https://sec.hypermedia.au/standards/finding/v1

Validates the finding standard.Raw schema (JSON).

FieldTypeRequiredConstraints
bomFormatstringyesone of: CycloneDX
specVersionstringyes= 1.7
serialNumberstringyespattern ^urn:uuid:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
versionintegeryes
metadataobjectyes
components
FND-003: exactly one data component — the finding document with its SHA-256 hash
arrayyesitems 1–1
signatureobjectyes

Also defines: propertyEntry