Skip to content

Commit fa5fd47

Browse files
fglockDevin
andcommitted
Review and improve SBOM design document for accuracy and clarity
Accuracy fixes: - Correct Gradle version catalog plugin syntax - Fix output paths to match actual CycloneDX defaults (build/reports/cyclonedx/) - Remove biased claim about SPDX tooling maturity - Fix "re-implemented" claim for Perl pragmas - Remove hallucinated version date for SBOM::CycloneDX - Correct claim about CPAN checksums Clarity improvements: - Add glossary explaining SBOM, CycloneDX, PURL, VEX, shaded JAR, Maven Central, CPAN - Better explain "why SBOM matters" with concrete use cases - Simplify Phase 2 options to single recommended approach - Add context for both Java and Perl developers - Improve code examples with comments Generated with [Devin](https://cli.devin.ai/docs) Co-Authored-By: Devin <noreply@cognition.ai>
1 parent 220769e commit fa5fd47

1 file changed

Lines changed: 119 additions & 136 deletions

File tree

0 commit comments

Comments
 (0)