Commit fa5fd47
Review and improve SBOM design document for accuracy and clarity
Accuracy fixes:
- Correct Gradle version catalog plugin syntax
- Fix output paths to match actual CycloneDX defaults (build/reports/cyclonedx/)
- Remove biased claim about SPDX tooling maturity
- Fix "re-implemented" claim for Perl pragmas
- Remove hallucinated version date for SBOM::CycloneDX
- Correct claim about CPAN checksums
Clarity improvements:
- Add glossary explaining SBOM, CycloneDX, PURL, VEX, shaded JAR, Maven Central, CPAN
- Better explain "why SBOM matters" with concrete use cases
- Simplify Phase 2 options to single recommended approach
- Add context for both Java and Perl developers
- Improve code examples with comments
Generated with [Devin](https://cli.devin.ai/docs)
Co-Authored-By: Devin <noreply@cognition.ai>1 parent 220769e commit fa5fd47
1 file changed
Lines changed: 119 additions & 136 deletions
0 commit comments