Skip to content

Navigation Menu

Sign in
Sign up

Bom-ref vs. bom-id? #671

andreas-hilti started this conversation in Ideas, Proposals, RFCs
Aug 10, 2025 · 1 comments · 2 replies
Discussion options

I'm wondering about the identifier "bom-ref": shouldn't this rather be called "bom-id"?

If you look at the description https://cyclonedx.org/docs/1.6/json/#components_items_bom-ref

An optional identifier which can be used to reference the component elsewhere in the BOM.

For me, the component has an identifier (which I'd rather call "bom-id"), and this bom-id is then referenced in other places, e.g. in dependencies https://cyclonedx.org/docs/1.6/json/#dependencies_items_ref

References a component or service by its bom-ref attribute

which should rather be:

References a component or service by its bom identifier attribute (bom-id)

Only where it is used/referenced, this is actually a reference.

Could this be considered for CycloneDX 2.0?
For me, the main benefit would be clarity and alignment with standard usage of the term "reference".

You must be logged in to vote

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
Comment options

I wouldn't mind having the additional clarity. Thanks for the suggestion. Will consider for 2.0.

Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

AltStyle によって変換されたページ (->オリジナル) /