Context
PR #364 raised SBOM export quality substantially (self-scan: CycloneDX 80.9/B, SPDX 78.2, NTIA-compliant, schema-clean in both formats). Two completeness fields remain empty by design: per-component supplier and description. Bomly does not fabricate them — heuristics like "supplier = PURL namespace" would put made-up assertions into a compliance artifact. This is also the one remaining EU-CRA profile error sbom-tools v0.1.22 reports against our output ("Direct dependency supplier (mandatory)", CRA Annex I, Part III / prEN 40000-1-3 [PRE-7-RQ-03]).
Proposal
Populate both fields during --enrich from sources that actually assert them:
- deps.dev already serves package metadata for the ecosystems it covers; extend
internal/matchers/depsdev to capture description and origin/publisher data plus VCS/homepage links, store them on sdk.Package (new fields — SDK contract change, released and pinned per the usual flow), and project them into both formats in internal/sbom/transform.go:
- CycloneDX:
component.supplier, component.description, externalReferences (vcs, website).
- SPDX:
PackageSupplier, PackageDescription (or PackageSummary), external references.
- Registry-native matchers (npm metadata, etc.) can contribute where deps.dev has no coverage.
- Emit only when a source asserts the data; absent stays absent.
Related (same completeness bucket, different source): CPE identifiers could be generated via the vendored syft CPE package and emitted as component.cpe / SPDX cpe23Type refs — worth considering in the same effort or a sibling issue.
Acceptance
bomly scan --enrich -o cyclonedx -o spdx fills supplier/description for packages the sources cover, in both formats.
- No fabricated values for uncovered packages.
- sbom-tools CRA validation of an enriched self-scan reports zero supplier errors for covered ecosystems; NTIA stays compliant; both formats stay schema-clean.
- Docs:
docs/SBOM.md "What Bomly puts in the SBOM" updated.
🤖 Generated with Claude Code
Context
PR #364 raised SBOM export quality substantially (self-scan: CycloneDX 80.9/B, SPDX 78.2, NTIA-compliant, schema-clean in both formats). Two completeness fields remain empty by design: per-component supplier and description. Bomly does not fabricate them — heuristics like "supplier = PURL namespace" would put made-up assertions into a compliance artifact. This is also the one remaining EU-CRA profile error sbom-tools v0.1.22 reports against our output ("Direct dependency supplier (mandatory)", CRA Annex I, Part III / prEN 40000-1-3 [PRE-7-RQ-03]).
Proposal
Populate both fields during
--enrichfrom sources that actually assert them:internal/matchers/depsdevto capture description and origin/publisher data plus VCS/homepage links, store them onsdk.Package(new fields — SDK contract change, released and pinned per the usual flow), and project them into both formats ininternal/sbom/transform.go:component.supplier,component.description,externalReferences(vcs,website).PackageSupplier,PackageDescription(orPackageSummary), external references.Related (same completeness bucket, different source): CPE identifiers could be generated via the vendored syft CPE package and emitted as
component.cpe/ SPDXcpe23Typerefs — worth considering in the same effort or a sibling issue.Acceptance
bomly scan --enrich -o cyclonedx -o spdxfills supplier/description for packages the sources cover, in both formats.docs/SBOM.md"What Bomly puts in the SBOM" updated.🤖 Generated with Claude Code