[ingestion/data-quality issue] CycloneDX 'pedigree' information #2313
Labels
bug
Something isn't working
data-quality
Things related to data quality and document ingestion
data-sources
Describe the bug
I would like to understand if an how in the Guac community there has been any investigation on how to ingest into guac's ontology the information from the CycloneDX
pedigree
, ref. https://cyclonedx.org/docs/1.5/json/#components_items_pedigreeTo Reproduce
No data ingested into Guac from the CycloneDX
pedigree
.Expected behavior
Nothing is expected, this issue is, first of all, for discussion.
Screenshots
If applicable, add screenshots to help explain your problem.
GUAC version
Current
main
branch, i.e. ea7ffafIngested document(s)
Can you share the documents that are used to reproduce the ingestion errors or showcase the data quality issues.
Additional context
To get the discussion started, I've drafted a first attempt for mapping CycloneDX
pedigree
into guac's ontology:ancestor
Derived from CDX Pedigree ancestor relationship
, consistent with SPDX approachdescendant
Derived from CDX Pedigree descendant relationship
, consistent with SPDX approachvariant
Derived from CDX Pedigree variant relationship
, consistent with SPDX approachcommit
Maybe derive them all together, in some way, from the “url” value? It looks opinionated
patch
note
The text was updated successfully, but these errors were encountered: