Publication BOM v1 Schema
Validates one L3 Publication BOM version. Shape-only: the finalisation-version check on the catalog pin and the disclosability of composed findings are verifier checks. Normative requirements: https://sec.hypermedia.au/standards/publication/v1
Validates the publication standard.Raw schema (JSON).
| Field | Type | Required | Constraints |
|---|---|---|---|
bomFormat | string | yes | one of: CycloneDX |
specVersion | string | yes | = 1.7 |
externalReferencesPUBL-004: the finalised case catalog, by document-form BOM-Link with its paired hash | array | yes | items 1–∞ |
serialNumber | string | yes | pattern ^urn:uuid:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ |
version | integer | yes | — |
metadata | object | yes | — |
componentsPUBL-003: exactly one data component — the rendered report with at least one approved-floor hash (SHA-384 or SHA-512) | array | yes | items 1–1 |
compositionsPUBL-005: aggregate complete; assemblies = the exact finding BOM-Links disclosed | array | yes | items 1–∞ |
signature | ref | yes | — |
Also defines: propertyEntryhashEntrysignature
