Skip to content

Publication BOM v1 Schema

Validates one L3 Publication BOM version. Shape-only: the finalisation-version check on the catalog pin and the disclosability of composed findings are verifier checks. Normative requirements: https://sec.hypermedia.au/standards/publication/v1

Validates the publication standard.Raw schema (JSON).

FieldTypeRequiredConstraints
bomFormatstringyesone of: CycloneDX
specVersionstringyes= 1.7
externalReferences
PUBL-004: the finalised case catalog, by document-form BOM-Link with its paired hash
arrayyesitems 1–∞
serialNumberstringyespattern ^urn:uuid:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
versionintegeryes—
metadataobjectyes—
components
PUBL-003: exactly one data component — the rendered report with at least one approved-floor hash (SHA-384 or SHA-512)
arrayyesitems 1–1
compositions
PUBL-005: aggregate complete; assemblies = the exact finding BOM-Links disclosed
arrayyesitems 1–∞
signaturerefyes—

Also defines: propertyEntryhashEntrysignature