Skip to content

Finding BOM v1 Schema

Validates one L2 Finding BOM version. Shape-only: provenanceRef resolution, author-identity equality with the provenance attestation, the disclosability condition, and supersession chains are verifier (adbom-cli) checks. Normative requirements: https://sec.hypermedia.au/standards/finding/v1

Validates the finding standard.Raw schema (JSON).

FieldTypeRequiredConstraints
bomFormatstringyesone of: CycloneDX
specVersionstringyes= 1.7
externalReferences
FND-004: the analysis-provenance attestation, by document-form BOM-Link with its paired hash
arrayyesitems 1–∞
serialNumberstringyespattern ^urn:uuid:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
versionintegeryes—
metadataobjectyes—
components
FND-003: exactly one data component — the finding document with at least one approved-floor hash (SHA-384 or SHA-512)
arrayyesitems 1–1
signaturerefyes—

Also defines: propertyEntryhashEntrysignature