[{"url":"https://api.github.com/repos/CycloneDX/specification/releases/333032842","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/333032842/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/333032842/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.7.1","id":333032842,"author":{"login":"jkowalleck","id":2765863,"node_id":"MDQ6VXNlcjI3NjU4NjM=","avatar_url":"https://avatars.githubusercontent.com/u/2765863?v=4","gravatar_id":"","url":"https://api.github.com/users/jkowalleck","html_url":"https://github.com/jkowalleck","followers_url":"https://api.github.com/users/jkowalleck/followers","following_url":"https://api.github.com/users/jkowalleck/following{/other_user}","gists_url":"https://api.github.com/users/jkowalleck/gists{/gist_id}","starred_url":"https://api.github.com/users/jkowalleck/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jkowalleck/subscriptions","organizations_url":"https://api.github.com/users/jkowalleck/orgs","repos_url":"https://api.github.com/users/jkowalleck/repos","events_url":"https://api.github.com/users/jkowalleck/events{/privacy}","received_events_url":"https://api.github.com/users/jkowalleck/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4T2a2K","tag_name":"1.7.1","target_commitish":"master","name":"1.7.1","draft":false,"immutable":true,"prerelease":false,"created_at":"2026-06-02T09:56:44Z","updated_at":"2026-06-02T10:10:35Z","published_at":"2026-06-02T10:10:35Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.7.1","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.7.1","body":"## Fixed – Schema Alignment\r\n* Protobuf: added the optional, repeated field `ModelCard.property` ([#726] via [#743])\r\n* XML: added the optional, repeated node `//modelCard/properties` ([#726] via [#743])\r\n* XML: changed the node `//modelCard/considerations/users/user` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/useCases/useCase` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/technicalLimitations/technicalLimitation` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/performanceTradeoffs/performanceTradeoff` from optional to optional and repeated ([#737] via [#744])\r\n\r\n## Tests\r\n* Added test cases for the updated schemas.\r\n\r\n[#726]: https://github.com/CycloneDX/specification/issues/726  \r\n[#743]: https://github.com/CycloneDX/specification/pull/743  \r\n[#737]: https://github.com/CycloneDX/specification/issues/737  \r\n[#744]: https://github.com/CycloneDX/specification/pull/744\r\n\r\n----\r\n\r\n## What's Changed\r\n* chore(deps): bump actions/upload-artifact from 4 to 5 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/711\r\n* ci: test use php8.4 by @jkowalleck in https://github.com/CycloneDX/specification/pull/708\r\n* ci: test use node24 by @jkowalleck in https://github.com/CycloneDX/specification/pull/709\r\n* ci: test use bufbuild/buf:1.58.0 by @jkowalleck in https://github.com/CycloneDX/specification/pull/710\r\n* Minor grammar correction for ECMA-424 by @stevespringett in https://github.com/CycloneDX/specification/pull/717\r\n* Editorial: Fix typos in descriptions by @gesa in https://github.com/CycloneDX/specification/pull/721\r\n* chore(deps): bump actions/checkout from 4 to 6 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/728\r\n* chore(deps): bump actions/setup-node from 4 to 6 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/723\r\n* chore(deps): bump actions/upload-artifact from 5 to 6 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/741\r\n* feat(registry): add XChaCha20-Poly1305 AEAD variant by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/755\r\n* fix(registry): correct TUAK naming and bcrypt pattern syntax by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/751\r\n* chore(deps): bump glob from 11.1.0 to 13.0.0 in /tools/src/test/js by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/730\r\n* feat(registry): add AES-CTR-HMAC-SHA1-96 suite pattern (RFC 3686) by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/771\r\n* feat(registry): add AES-CMAC-PRF-128 (RFC 4615) by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/768\r\n* feat(registry): add HPKE (RFC 9180) to Cryptography Registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/766\r\n* fix(registry): correct RFC 3610 DOI reference by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/762\r\n* fix(registry): remove duplicate BLAKE2b-HMAC variant (#752) by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/753\r\n* Add HPKE to algorithmFamiliesEnum by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/810\r\n* chore(registry): normalize RFC standard naming (remove space before number) by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/808\r\n* fix(registry): correct SP800-185 reference URL by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/803\r\n* Update ratings descriptions in schema files for clarity on VEX usage by @fahedouch in https://github.com/CycloneDX/specification/pull/722\r\n* fix(proto): correct 'plain text' typo in AttachedText comment by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/786\r\n* chore: SPDX licenses bump automation by @jkowalleck in https://github.com/CycloneDX/specification/pull/703\r\n* feat(registry): add SPAKE2 (RFC 9382) and SPAKE2+ (RFC 9383) by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/798\r\n* feat(registry): add OPAQUE (RFC 9807) by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/796\r\n* Add Argon2 (RFC 9106) to Cryptography Registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/793\r\n* Add SP800-90A DRBGs to Cryptography Registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/790\r\n* Add UMAC (RFC4418) to Cryptography Registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/788\r\n* feat(registry): add scrypt (RFC7914) to Cryptography Registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/784\r\n* feat(registry): add AES-SIV AEAD variant (RFC 5297) by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/764\r\n* Feat/crypto registry aes gcm siv by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/759\r\n* fix(registry): correct ANSI INCITS 92-1981 reference URL by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/814\r\n* Fix HMACXOF typo by @jvdsn in https://github.com/CycloneDX/specification/pull/823\r\n* Add ShangMi (SM2/SM3/SM4/SM9) algorithm families by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/812\r\n* Add SRP (RFC2945/RFC5054) and J-PAKE (RFC8236) to Cryptography Registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/792\r\n* Crypto defs sync by @stevespringett in https://github.com/CycloneDX/specification/pull/825\r\n* Changed to using PRs due to branch protection by @stevespringett in https://github.com/CycloneDX/specification/pull/826\r\n* Crypto defs sync by @stevespringett in https://github.com/CycloneDX/specification/pull/827\r\n* chore: update algorithm families by @github-actions[bot] in https://github.com/CycloneDX/specification/pull/828\r\n* feat: bump SPDX License IDs -  v1.0-3.28.0 by @github-actions[bot] in https://github.com/CycloneDX/specification/pull/829\r\n* chore: run tests by @jkowalleck in https://github.com/CycloneDX/specification/pull/842\r\n* fix(schema): correct typos in BOM 1.6/1.7 JSON Schema and XSD by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/850\r\n* fix(crypto-registry): normalize RFC/FIPS standard name formatting by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/847\r\n* chore: update algorithm families by @github-actions[bot] in https://github.com/CycloneDX/specification/pull/843\r\n* feat: enum labels for spdx.schema.json by @jkowalleck in https://github.com/CycloneDX/specification/pull/839\r\n* chore: harden schema validators by @jkowalleck in https://github.com/CycloneDX/specification/pull/859\r\n* Added missing scarf to docs. by @stevespringett in https://github.com/CycloneDX/specification/pull/860\r\n* Update crypto definitions by @bhess in https://github.com/CycloneDX/specification/pull/844\r\n* chore: update algorithm families by @github-actions[bot] in https://github.com/CycloneDX/specification/pull/852\r\n* Modernize docgen: Bootstrap 5.3.8, drop jQuery/Font Awesome, add centralized mega menu by @stevespringett in https://github.com/CycloneDX/specification/pull/863\r\n* JSON doc performance improvements by @stevespringett in https://github.com/CycloneDX/specification/pull/865\r\n* docs: remove buf comments by @jkowalleck in https://github.com/CycloneDX/specification/pull/880\r\n* docs: fix scroll-padding-top for XML by @jkowalleck in https://github.com/CycloneDX/specification/pull/886\r\n* Add AES-OCB to cryptography registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/885\r\n* Fix SipHash primitive classification in cryptography registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/883\r\n* Add ANSI KDFs by @jvdsn in https://github.com/CycloneDX/specification/pull/881\r\n* Deduplicate MD4 and MD5 entries in cryptography registry by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/879\r\n* Add SP800-56C family by @jvdsn in https://github.com/CycloneDX/specification/pull/877\r\n* Remove dash from SHA-3 hash algorithms by @jvdsn in https://github.com/CycloneDX/specification/pull/871\r\n* Remove dash from EdDSA by @jvdsn in https://github.com/CycloneDX/specification/pull/870\r\n* Add hashAlgorithm to IKE-PRF by @jvdsn in https://github.com/CycloneDX/specification/pull/873\r\n* Separate out AES KW / KWP by @jvdsn in https://github.com/CycloneDX/specification/pull/869\r\n* Add TLS-PRF family by @jvdsn in https://github.com/CycloneDX/specification/pull/875\r\n* Fixed JSON issue by @stevespringett in https://github.com/CycloneDX/specification/pull/894\r\n* Add SSH-KDF to cryptography registry by @jvdsn in https://github.com/CycloneDX/specification/pull/899\r\n* chore: pin GitHub Actions to immutable commit SHAs by @Copilot in https://github.com/CycloneDX/specification/pull/908\r\n* Add RSA-X931 by @jvdsn in https://github.com/CycloneDX/specification/pull/868\r\n* chore(workflows): add zizmor security gate and harden Actions credential handling by @Copilot in https://github.com/CycloneDX/specification/pull/925\r\n* fix: add missing modelCard.properties to XML + Protobuf schemas by @wiebe-vandendriessche in https://github.com/CycloneDX/specification/pull/743\r\n* fix: allow multiple entries for ModelCard considerations lists in xml by @wiebe-vandendriessche in https://github.com/CycloneDX/specification/pull/744\r\n* fix: correct GOST 28147 algorithm names by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/921\r\n* fix: correct BLS12 algorithm pattern by @Mehrn0ush in https://github.com/CycloneDX/specification/pull/923\r\n* chore(deps): bump shivammathur/setup-php from 2.37.0 to 2.37.1 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/938\r\n* chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/939\r\n* CycloneDX 1.7.1 - Schema Alignment & Typo-/Bug‑Fix Release by @jkowalleck in https://github.com/CycloneDX/specification/pull/932\r\n\r\n## New Contributors\r\n* @gesa made their first contribution in https://github.com/CycloneDX/specification/pull/721\r\n* @fahedouch made their first contribution in https://github.com/CycloneDX/specification/pull/722\r\n* @github-actions[bot] made their first contribution in https://github.com/CycloneDX/specification/pull/828\r\n* @Copilot made their first contribution in https://github.com/CycloneDX/specification/pull/908\r\n* @wiebe-vandendriessche made their first contribution in https://github.com/CycloneDX/specification/pull/743\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.7...1.7.1","reactions":{"url":"https://api.github.com/repos/CycloneDX/specification/releases/333032842/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"mentions_count":9},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/333045057","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/333045057/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/333045057/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.6.2","id":333045057,"author":{"login":"jkowalleck","id":2765863,"node_id":"MDQ6VXNlcjI3NjU4NjM=","avatar_url":"https://avatars.githubusercontent.com/u/2765863?v=4","gravatar_id":"","url":"https://api.github.com/users/jkowalleck","html_url":"https://github.com/jkowalleck","followers_url":"https://api.github.com/users/jkowalleck/followers","following_url":"https://api.github.com/users/jkowalleck/following{/other_user}","gists_url":"https://api.github.com/users/jkowalleck/gists{/gist_id}","starred_url":"https://api.github.com/users/jkowalleck/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jkowalleck/subscriptions","organizations_url":"https://api.github.com/users/jkowalleck/orgs","repos_url":"https://api.github.com/users/jkowalleck/repos","events_url":"https://api.github.com/users/jkowalleck/events{/privacy}","received_events_url":"https://api.github.com/users/jkowalleck/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4T2d1B","tag_name":"1.6.2","target_commitish":"1.6.2-dev","name":"1.6.2","draft":false,"immutable":true,"prerelease":false,"created_at":"2026-05-22T08:48:00Z","updated_at":"2026-06-02T10:40:01Z","published_at":"2026-06-02T10:36:32Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.6.2","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.6.2","body":"> [!NOTE]  \r\n> This release is a backport of the fixes in [v1.7.1](https://github.com/CycloneDX/specification/releases/tag/1.7.1)\r\n\r\n----\r\n\r\n## Fixed – Schema Alignment\r\n* Protobuf: added the optional, repeated field `ModelCard.property` ([#726] via [#743])\r\n* XML: added the optional, repeated node `//modelCard/properties` ([#726] via [#743])\r\n* XML: changed the node `//modelCard/considerations/users/user` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/useCases/useCase` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/technicalLimitations/technicalLimitation` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/performanceTradeoffs/performanceTradeoff` from optional to optional and repeated ([#737] via [#744])\r\n\r\n## Docs – Schema Alignment\r\n- Backported streamlined documentation.\r\n\r\n## Tests\r\n- Backported test cases.\r\n- Backported test runners.\r\n\r\n[#726]: https://github.com/CycloneDX/specification/issues/726\r\n[#743]: https://github.com/CycloneDX/specification/pull/743\r\n[#737]: https://github.com/CycloneDX/specification/issues/737\r\n[#744]: https://github.com/CycloneDX/specification/pull/744\r\n\r\n----\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.6.1...1.6.2"},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/333057865","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/333057865/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/333057865/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.5.1","id":333057865,"author":{"login":"jkowalleck","id":2765863,"node_id":"MDQ6VXNlcjI3NjU4NjM=","avatar_url":"https://avatars.githubusercontent.com/u/2765863?v=4","gravatar_id":"","url":"https://api.github.com/users/jkowalleck","html_url":"https://github.com/jkowalleck","followers_url":"https://api.github.com/users/jkowalleck/followers","following_url":"https://api.github.com/users/jkowalleck/following{/other_user}","gists_url":"https://api.github.com/users/jkowalleck/gists{/gist_id}","starred_url":"https://api.github.com/users/jkowalleck/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jkowalleck/subscriptions","organizations_url":"https://api.github.com/users/jkowalleck/orgs","repos_url":"https://api.github.com/users/jkowalleck/repos","events_url":"https://api.github.com/users/jkowalleck/events{/privacy}","received_events_url":"https://api.github.com/users/jkowalleck/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4T2g9J","tag_name":"1.5.1","target_commitish":"1.5.1-dev","name":"1.5.1","draft":false,"immutable":true,"prerelease":false,"created_at":"2026-05-22T08:47:25Z","updated_at":"2026-06-02T11:04:51Z","published_at":"2026-06-02T11:04:51Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.5.1","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.5.1","body":"> [!NOTE]  \r\n> This release is a backport of the fixes in [v1.7.1](https://github.com/CycloneDX/specification/releases/tag/1.7.1)\r\n\r\n----\r\n\r\n\r\n## Fixed – Schema Alignment\r\n* JSON: the `$.version` property is no longer required because it had a default value already.\r\n* Protobuf: added the optional, repeated field `ModelCard.property` ([#726] via [#743])\r\n* XML: added the optional, repeated node `//modelCard/properties` ([#726] via [#743])\r\n* XML: changed the node `//modelCard/considerations/users/user` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/useCases/useCase` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/technicalLimitations/technicalLimitation` from optional to optional and repeated ([#737] via [#744])\r\n* XML: changed the node `//modelCard/considerations/performanceTradeoffs/performanceTradeoff` from optional to optional and repeated ([#737] via [#744])\r\n\r\n## Docs – Schema Alignment\r\n- Backported streamlined documentation.\r\n\r\n## Tests\r\n- Backported test cases.\r\n- Backported test runners.\r\n\r\n## CI\r\n- Modernized CI runners where needed.\r\n\r\n[#726]: https://github.com/CycloneDX/specification/issues/726\r\n[#743]: https://github.com/CycloneDX/specification/pull/743\r\n[#737]: https://github.com/CycloneDX/specification/issues/737\r\n[#744]: https://github.com/CycloneDX/specification/pull/744\r\n\r\n\r\n----\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.5...1.5.1"},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/256058288","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/256058288/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/256058288/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.7","id":256058288,"author":{"login":"jkowalleck","id":2765863,"node_id":"MDQ6VXNlcjI3NjU4NjM=","avatar_url":"https://avatars.githubusercontent.com/u/2765863?v=4","gravatar_id":"","url":"https://api.github.com/users/jkowalleck","html_url":"https://github.com/jkowalleck","followers_url":"https://api.github.com/users/jkowalleck/followers","following_url":"https://api.github.com/users/jkowalleck/following{/other_user}","gists_url":"https://api.github.com/users/jkowalleck/gists{/gist_id}","starred_url":"https://api.github.com/users/jkowalleck/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jkowalleck/subscriptions","organizations_url":"https://api.github.com/users/jkowalleck/orgs","repos_url":"https://api.github.com/users/jkowalleck/repos","events_url":"https://api.github.com/users/jkowalleck/events{/privacy}","received_events_url":"https://api.github.com/users/jkowalleck/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4PQyOw","tag_name":"1.7","target_commitish":"master","name":"1.7","draft":false,"immutable":false,"prerelease":false,"created_at":"2025-10-21T15:09:58Z","updated_at":"2025-10-21T15:50:03Z","published_at":"2025-10-21T15:35:08Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.7","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.7","body":"Major new additions include support for Data Provenance & Citations, Intellectual Property Transparency, Cryptographic Assurance (CBOM),  extended License Details. and external components (SBOM).\r\n\r\n**Announcement**: https://cyclonedx.org/news/cyclonedx-v1.7-released/\r\n\r\n----\r\n\r\n## Fixed\r\n\r\n* XML schema: add type for `ComponentData` sub-elements ([#600] via [#601])\r\n* JSON schema: added the correct `deprecated` mark for already deprecated structures (via [a973a6b])\r\n\r\n## Deprecated\r\n\r\n* Deprecated various fields and structures related to _cryptographic transparency_ - _CBOM_ . (via [#657])  \r\n  Use the newly added structures and fields for detailing the information instead.\r\n\r\n## Changed\r\n\r\n* Extended the scope of _formulations_. (via [#647])\r\n  From now on, _formulations_ may be used to describe how any referencable object within the BOM came together, including components, services, metadata, declarations, or the BOM itself.\r\n  Before, it was restricted to components and services.\r\n\r\n## Added\r\n\r\n* Support for _external components_ with _version-ranges_ ([#321] via [#586])\r\n* Support for _multiple_ SPDX License Expressions alongside with other licenses ([#454] via [#582])\r\n* Support for _Streebog hashing algorithm_ ([#485] via [#525])\r\n* Support for license expression _details and properties_ ([#549], [#554] via [#599])\r\n* Support for expressing BOM distribution constraints with the _Traffic Light Protocol_ (TLP) in metadata ([#595] via [#604], [#653])\r\n* Support for representing _patent information_ ([#596] via [#597])\r\n* Support for _properties_ on external-references ([#608] via [#610])\r\n* Support for _citations_ ([#630] via [#629])\r\n* Support for detailing _cryptographic transparency_ information - _CBOM_ ([#569] via [#657])\r\n\r\n## Documentation\r\n\r\n* Elaborated component classification \"platform\", explicitly expressed that it includes just-in-time compilers and interpreters ([#233] via [#647])\r\n* Removed the term \"optional\" from the schema where the definition was already unambiguous ([#616], [#649] via [#680])\r\n\r\n## Test data\r\n\r\n* Add test data for CycloneDX 1.7 implementations in XML, JSON, Protobuf\r\n\r\n\r\n[#233]: https://github.com/CycloneDX/specification/issues/233\r\n[#321]: https://github.com/CycloneDX/specification/issues/321\r\n[#454]: https://github.com/CycloneDX/specification/issues/454\r\n[#485]: https://github.com/CycloneDX/specification/issues/485\r\n[#525]: https://github.com/CycloneDX/specification/pull/525\r\n[#549]: https://github.com/CycloneDX/specification/issues/549\r\n[#554]: https://github.com/CycloneDX/specification/issues/554\r\n[#569]: https://github.com/CycloneDX/specification/issues/569\r\n[#582]: https://github.com/CycloneDX/specification/pull/582\r\n[#586]: https://github.com/CycloneDX/specification/pull/586\r\n[#595]: https://github.com/CycloneDX/specification/issues/595\r\n[#596]: https://github.com/CycloneDX/specification/issues/596\r\n[#597]: https://github.com/CycloneDX/specification/pull/597\r\n[#599]: https://github.com/CycloneDX/specification/pull/599\r\n[#600]: https://github.com/CycloneDX/specification/issues/600\r\n[#601]: https://github.com/CycloneDX/specification/pull/601\r\n[#604]: https://github.com/CycloneDX/specification/pull/604\r\n[#608]: https://github.com/CycloneDX/specification/issues/608\r\n[#610]: https://github.com/CycloneDX/specification/pull/610\r\n[#616]: https://github.com/CycloneDX/specification/issues/616\r\n[#629]: https://github.com/CycloneDX/specification/issues/629\r\n[#630]: https://github.com/CycloneDX/specification/pull/630\r\n[#647]: https://github.com/CycloneDX/specification/pull/647\r\n[#649]: https://github.com/CycloneDX/specification/issues/649\r\n[#653]: https://github.com/CycloneDX/specification/pull/653\r\n[#657]: https://github.com/CycloneDX/specification/pull/657\r\n[#680]: https://github.com/CycloneDX/specification/pull/680\r\n[a973a6b]: https://github.com/CycloneDX/specification/pull/511/commits/a973a6bfec2eb3277d8d91e3bffc816784ee265b\r\n\r\n-----\r\n\r\n## What's Changed\r\n* chore(deps): bump org.apache.maven.plugins:maven-surefire-plugin from 3.4.0 to 3.5.1 in /tools by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/527\r\n* chore(deps): bump commons-io:commons-io from 2.16.1 to 2.17.0 in /tools by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/523\r\n* Adapt test samples to ensure consistency between the different formats by @andreas-hilti in https://github.com/CycloneDX/specification/pull/514\r\n* fix: typos in schemas 1.6 by @weaversa in https://github.com/CycloneDX/specification/pull/550\r\n* chore(dev-deps): tools use cyclonedx-core-java v10.0.0 by @jkowalleck in https://github.com/CycloneDX/specification/pull/552\r\n* remove unused config file by @jkowalleck in https://github.com/CycloneDX/specification/pull/558\r\n* chore(deps): update opis/json-schema requirement from 2.3 to 2.4.1 in /tools/src/test/php by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/560\r\n* docs: align media types in table by @jkowalleck in https://github.com/CycloneDX/specification/pull/561\r\n* docs: Recognized file patterns by @jkowalleck in https://github.com/CycloneDX/specification/pull/562\r\n* docs: fix some docs image-urls by @jkowalleck in https://github.com/CycloneDX/specification/pull/566\r\n* docs: docsgen restructure output for website by @jkowalleck in https://github.com/CycloneDX/specification/pull/570\r\n* docs: docgen proto with `protoc-gen-doc` by @jkowalleck in https://github.com/CycloneDX/specification/pull/557\r\n* docs: docsgen theme and linkd for proto by @jkowalleck in https://github.com/CycloneDX/specification/pull/571\r\n* docs: docsge fix title in `<meta>` elements by @jkowalleck in https://github.com/CycloneDX/specification/pull/572\r\n* docs: docsgen proto html scroll fixes by @jkowalleck in https://github.com/CycloneDX/specification/pull/573\r\n* chore: introduce PR template by @jkowalleck in https://github.com/CycloneDX/specification/pull/579\r\n* pull_request_template tell about rules by @jkowalleck in https://github.com/CycloneDX/specification/pull/580\r\n* tests: testcases initial 1.7 by @jkowalleck in https://github.com/CycloneDX/specification/pull/583\r\n* docs: docsgen latest first by @jkowalleck in https://github.com/CycloneDX/specification/pull/584\r\n* feat(DX): add xml catalog for XSD by @Nicolas-Peiffer in https://github.com/CycloneDX/specification/pull/479\r\n* fix: version range spec url by @jkowalleck in https://github.com/CycloneDX/specification/pull/581\r\n* docs: allow SchemaDocs HTML generator run for one(specific) CDX version by @jkowalleck in https://github.com/CycloneDX/specification/pull/587\r\n* chore: bump tools buf 1.50.0 by @jkowalleck in https://github.com/CycloneDX/specification/pull/588\r\n* chore: test protobuf acknowledged BC by @jkowalleck in https://github.com/CycloneDX/specification/pull/589\r\n* tests: php QA tests run offline by @jkowalleck in https://github.com/CycloneDX/specification/pull/594\r\n* tests(Java): run test against actual schema files by @ppkarwasz in https://github.com/CycloneDX/specification/pull/592\r\n* Fix missing type definitions for ComponentData subelements in XML by @andreas-hilti in https://github.com/CycloneDX/specification/pull/601\r\n* Add support for Streebog hashing algorithm by @volkdm in https://github.com/CycloneDX/specification/pull/525\r\n* feat: support for external components with version-ranges by @jkowalleck in https://github.com/CycloneDX/specification/pull/586\r\n* docs: modernize build workflow badges by @jkowalleck in https://github.com/CycloneDX/specification/pull/625\r\n* Update cryptography-defs.json by @bhess in https://github.com/CycloneDX/specification/pull/622\r\n* Extends cryptography-defs.json by @bhess in https://github.com/CycloneDX/specification/pull/644\r\n* feat: Add support for TLP marking in metadata by @anthonyharrison in https://github.com/CycloneDX/specification/pull/604\r\n* feat: add custom properties to external references  by @Urist-McGit in https://github.com/CycloneDX/specification/pull/610\r\n* feat: license expression details and properties - text attachment, licensing, etc by @jkowalleck in https://github.com/CycloneDX/specification/pull/599\r\n* Add support for representing patent information by @stevespringett in https://github.com/CycloneDX/specification/pull/597\r\n* Improve wording of issue templates by @sschuberth in https://github.com/CycloneDX/specification/pull/651\r\n* JIT compilers & interpreters are \"platforms\" by @jkowalleck in https://github.com/CycloneDX/specification/pull/647\r\n* Add python script to generate algorithm families by @n1ckl0sk0rtge in https://github.com/CycloneDX/specification/pull/645\r\n* Review algorithm list, apply rules for patterns by @bhess in https://github.com/CycloneDX/specification/pull/646\r\n* Add missing changes  by @n1ckl0sk0rtge in https://github.com/CycloneDX/specification/pull/658\r\n* CBOM 1.7: Update test cases & a few schema fixes/extensions by @bhess in https://github.com/CycloneDX/specification/pull/661\r\n* feat: support multi license mix by @jkowalleck in https://github.com/CycloneDX/specification/pull/582\r\n* [1.7] citation:  proposed changes 2 by @jkowalleck in https://github.com/CycloneDX/specification/pull/667\r\n* Extend crypto definitions by @bhess in https://github.com/CycloneDX/specification/pull/672\r\n* [1.7] Added citation support and test cases. by @stevespringett in https://github.com/CycloneDX/specification/pull/630\r\n* refactor: metadata distribution to be an object by @jkowalleck in https://github.com/CycloneDX/specification/pull/653\r\n* fix: remove the word \"optional\", align some docs by @jkowalleck in https://github.com/CycloneDX/specification/pull/680\r\n* Extend crypto definitions by @bhess in https://github.com/CycloneDX/specification/pull/676\r\n* [1.7] - Updates from CBOM working group - remove any BREAKING CHANGES for ProtoBuf by @jkowalleck in https://github.com/CycloneDX/specification/pull/677\r\n* [1.7] - Updates from CBOM working group by @stevespringett in https://github.com/CycloneDX/specification/pull/657\r\n* Updating SPDX license list to 3.27.0 by @jkowalleck in https://github.com/CycloneDX/specification/pull/683\r\n* fix(XML): fixed `aggregateType` docs for `incomplete_first_party_*` by @lime in https://github.com/CycloneDX/specification/pull/684\r\n* fix(XML): fixed `aggregateType` docs for `incomplete_first_party_*` by @jkowalleck in https://github.com/CycloneDX/specification/pull/686\r\n* chore(deps): bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in /tools by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/687\r\n* chore(deps): bump actions/setup-java from 4 to 5 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/695\r\n* chore(deps): bump actions/setup-python from 5 to 6 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/694\r\n* chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/693\r\n* chore(deps): bump actions/setup-node from 4 to 5 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/692\r\n* chore: GH workflow permissions by @jkowalleck in https://github.com/CycloneDX/specification/pull/655\r\n* reorder readme header by @jkowalleck in https://github.com/CycloneDX/specification/pull/701\r\n* [1.7] docs: update link to version-range-spec by @jkowalleck in https://github.com/CycloneDX/specification/pull/700\r\n* docs: update link to version-range-spec by @jkowalleck in https://github.com/CycloneDX/specification/pull/699\r\n* chore(deps): update opis/json-schema requirement from 2.4.1 to 2.6.0 in /tools/src/test/php by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/707\r\n* chore(deps): bump actions/setup-node from 5 to 6 by @dependabot[bot] in https://github.com/CycloneDX/specification/pull/706\r\n* v1.7 by @jkowalleck in https://github.com/CycloneDX/specification/pull/511\r\n\r\n## New Contributors\r\n* @weaversa made their first contribution in https://github.com/CycloneDX/specification/pull/550\r\n* @ppkarwasz made their first contribution in https://github.com/CycloneDX/specification/pull/592\r\n* @volkdm made their first contribution in https://github.com/CycloneDX/specification/pull/525\r\n* @anthonyharrison made their first contribution in https://github.com/CycloneDX/specification/pull/604\r\n* @Urist-McGit made their first contribution in https://github.com/CycloneDX/specification/pull/610\r\n* @sschuberth made their first contribution in https://github.com/CycloneDX/specification/pull/651\r\n* @n1ckl0sk0rtge made their first contribution in https://github.com/CycloneDX/specification/pull/645\r\n* @lime made their first contribution in https://github.com/CycloneDX/specification/pull/684\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.6.1...1.7","reactions":{"url":"https://api.github.com/repos/CycloneDX/specification/releases/256058288/reactions","total_count":8,"+1":2,"-1":0,"laugh":0,"hooray":2,"confused":0,"heart":3,"rocket":1,"eyes":0},"mentions_count":14},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/184175894","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/184175894/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/184175894/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.6.1","id":184175894,"author":{"login":"jkowalleck","id":2765863,"node_id":"MDQ6VXNlcjI3NjU4NjM=","avatar_url":"https://avatars.githubusercontent.com/u/2765863?v=4","gravatar_id":"","url":"https://api.github.com/users/jkowalleck","html_url":"https://github.com/jkowalleck","followers_url":"https://api.github.com/users/jkowalleck/followers","following_url":"https://api.github.com/users/jkowalleck/following{/other_user}","gists_url":"https://api.github.com/users/jkowalleck/gists{/gist_id}","starred_url":"https://api.github.com/users/jkowalleck/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jkowalleck/subscriptions","organizations_url":"https://api.github.com/users/jkowalleck/orgs","repos_url":"https://api.github.com/users/jkowalleck/repos","events_url":"https://api.github.com/users/jkowalleck/events{/privacy}","received_events_url":"https://api.github.com/users/jkowalleck/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4K-k0W","tag_name":"1.6.1","target_commitish":"master","name":"1.6.1","draft":false,"immutable":false,"prerelease":false,"created_at":"2024-11-07T15:16:59Z","updated_at":"2024-11-07T16:02:57Z","published_at":"2024-11-07T15:19:40Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.6.1","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.6.1","body":"Functionally equivalent to CycloneDX 1.6.0 but with bug fixes to the XML/JSON/ProtoBuf implementations, and spelling, grammar and other editorial improvements.\r\n\r\n----\r\n\r\n## What's Changed\r\n* tests: annotate schema for test resources of CDX1.6 JSON by @jkowalleck in https://github.com/CycloneDX/specification/pull/423\r\n* chore: depedabot for all used ecosystems by @jkowalleck in https://github.com/CycloneDX/specification/pull/424\r\n* chore(dependencies): bump bufbuild/buf:1.30.1 by @jkowalleck in https://github.com/CycloneDX/specification/pull/431\r\n* chore(deps): bump ajv-formats from 2.1.1 to 3.0.1 in /tools/src/test/js by @dependabot in https://github.com/CycloneDX/specification/pull/430\r\n* docs: annotate protobuf licenses by @jkowalleck in https://github.com/CycloneDX/specification/pull/468\r\n* chore(deps): bump org.apache.commons:commons-text from 1.2 to 1.12.0 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/439\r\n* chore(deps): bump commons-io:commons-io from 2.7 to 2.16.1 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/429\r\n* chore(deps): bump org.apache.maven.plugins:maven-surefire-plugin from 3.0.0-M5 to 3.2.5 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/428\r\n* Fix(1.6spec): Fixed typo in componentEvidence description by @Petzys in https://github.com/CycloneDX/specification/pull/451\r\n* issue451-streamline by @jkowalleck in https://github.com/CycloneDX/specification/pull/475\r\n* tests:  Update to cyclonedx-core-java-9.0.2 for test runners by @Nicolas-Peiffer in https://github.com/CycloneDX/specification/pull/480\r\n* tests: Adding 1.6 valid and invalid test files in the Java tests by @Nicolas-Peiffer in https://github.com/CycloneDX/specification/pull/482\r\n* chore(deps): bump org.apache.maven.plugins:maven-surefire-plugin from 3.2.5 to 3.3.0 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/484\r\n* Update pom.xml by @jkowalleck in https://github.com/CycloneDX/specification/pull/489\r\n* docs: revisit example urls in spec 1.6 by @jkowalleck in https://github.com/CycloneDX/specification/pull/490\r\n* chore(deps): bump glob from 10.4.5 to 11.0.0 in /tools/src/test/js by @dependabot in https://github.com/CycloneDX/specification/pull/496\r\n* Add space after colon by @tamir-alltrue-ai in https://github.com/CycloneDX/specification/pull/494\r\n* 1.6 ecma by @stevespringett in https://github.com/CycloneDX/specification/pull/478\r\n* chore(deps): bump org.apache.maven.plugins:maven-surefire-plugin from 3.3.0 to 3.4.0 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/504\r\n* chore(deps): bump org.apache.commons:commons-lang3 from 3.6 to 3.16.0 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/499\r\n* chore(dependencies): bump Saxon-HE from 9.9.1-8 to 10.9 by @jkowalleck in https://github.com/CycloneDX/specification/pull/432\r\n* fix: add missing cryptoRef to `cryptoProperties.protocolPropertiesfor` XML/PB by @jkowalleck in https://github.com/CycloneDX/specification/pull/502\r\n* fix: ProtoBuf evidence not repeated, but optional by @jkowalleck in https://github.com/CycloneDX/specification/pull/425\r\n* 1.6 ecma -- docs carry over by @jkowalleck in https://github.com/CycloneDX/specification/pull/512\r\n* fix: revert PR #425 by @jkowalleck in https://github.com/CycloneDX/specification/pull/516\r\n* fix(ProtoBuff): component evidence should be optional, istead of repeated by @jkowalleck in https://github.com/CycloneDX/specification/pull/517\r\n* tests: fix ProtoBuf breaking detection to be wire-only by @jkowalleck in https://github.com/CycloneDX/specification/pull/532\r\n* tests: bump docker image from `bufbuild/buf:1.30.1` to `:1.46.0` by @jkowalleck in https://github.com/CycloneDX/specification/pull/519\r\n* tests: fix BrotoBuf BCcheck on version-level by @jkowalleck in https://github.com/CycloneDX/specification/pull/536\r\n* tests: fix BrotoBuf test reports by @jkowalleck in https://github.com/CycloneDX/specification/pull/537\r\n* fix(ProtoBuf): add ExternalReterence Type `EXTERNAL_REFERENCE_TYPE_RELEASE_NOTES` by @jkowalleck in https://github.com/CycloneDX/specification/pull/531\r\n* fix(ProtoBuf,XML): component data repeatable by @jkowalleck in https://github.com/CycloneDX/specification/pull/530\r\n* fix(ProtoBuf): `Component.evidence` optional by @jkowalleck in https://github.com/CycloneDX/specification/pull/534\r\n* fix(ProtoBuf): add `LicenseExpression.bom_ref` by @jkowalleck in https://github.com/CycloneDX/specification/pull/529\r\n* docs: transfer spec docs to ProtoBuf 1.6 by @jkowalleck in https://github.com/CycloneDX/specification/pull/539\r\n* docs: transfer specdocs to XML 1.6 by @jkowalleck in https://github.com/CycloneDX/specification/pull/540\r\n* fix(xml): requirement descriptions should be unbounded by @hakandilek in https://github.com/CycloneDX/specification/pull/533\r\n* chore: prep v1.6.1 by @jkowalleck in https://github.com/CycloneDX/specification/pull/535\r\n* chore(deps): bump org.apache.commons:commons-lang3 from 3.16.0 to 3.17.0 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/509\r\n\r\n## New Contributors\r\n* @Petzys made their first contribution in https://github.com/CycloneDX/specification/pull/451\r\n* @Nicolas-Peiffer made their first contribution in https://github.com/CycloneDX/specification/pull/480\r\n* @tamir-alltrue-ai made their first contribution in https://github.com/CycloneDX/specification/pull/494\r\n* @hakandilek made their first contribution in https://github.com/CycloneDX/specification/pull/533\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.6...1.6.1","reactions":{"url":"https://api.github.com/repos/CycloneDX/specification/releases/184175894/reactions","total_count":3,"+1":0,"-1":0,"laugh":0,"hooray":2,"confused":0,"heart":0,"rocket":1,"eyes":0},"mentions_count":7},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/150328245","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/150328245/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/150328245/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.6","id":150328245,"author":{"login":"stevespringett","id":3878933,"node_id":"MDQ6VXNlcjM4Nzg5MzM=","avatar_url":"https://avatars.githubusercontent.com/u/3878933?v=4","gravatar_id":"","url":"https://api.github.com/users/stevespringett","html_url":"https://github.com/stevespringett","followers_url":"https://api.github.com/users/stevespringett/followers","following_url":"https://api.github.com/users/stevespringett/following{/other_user}","gists_url":"https://api.github.com/users/stevespringett/gists{/gist_id}","starred_url":"https://api.github.com/users/stevespringett/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/stevespringett/subscriptions","organizations_url":"https://api.github.com/users/stevespringett/orgs","repos_url":"https://api.github.com/users/stevespringett/repos","events_url":"https://api.github.com/users/stevespringett/events{/privacy}","received_events_url":"https://api.github.com/users/stevespringett/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4I9dO1","tag_name":"1.6","target_commitish":"master","name":"1.6","draft":false,"immutable":false,"prerelease":false,"created_at":"2024-04-09T05:16:16Z","updated_at":"2024-04-09T20:05:37Z","published_at":"2024-04-09T05:18:59Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.6","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.6","body":"Major new additions include support for cryptographic assets (CBOM) and CycloneDX Attestations (CDXA). CycloneDX v1.6 forms the basis of a future Ecma International standard.\r\n\r\n**Announcement**: <https://cyclonedx.org/news/cyclonedx-v1.6-released/>\r\n\r\n----\r\n\r\n## Added\r\n\r\n* Core enhancement: Cryptography Bill of Materials — CBOM ([#171](https://github.com/CycloneDX/specification/issues/171), [#291](https://github.com/CycloneDX/specification/issues/291) via [#347](https://github.com/CycloneDX/specification/pull/347))\r\n* Core enhancement: Attestation — CDXA ([#192](https://github.com/CycloneDX/specification/issues/192) via [#348](https://github.com/CycloneDX/specification/pull/348))\r\n* Feature to express the URL to source distribution ([#98](https://github.com/CycloneDX/specification/issues/98) via [#269](https://github.com/CycloneDX/specification/pull/269))\r\n* Feature to express the URL to RFC 9116 compliant documents ([#380](https://github.com/CycloneDX/specification/issues/380) via [#381](https://github.com/CycloneDX/specification/pull/381))\r\n* Feature to express tags/keywords for services and components (via [#383](https://github.com/CycloneDX/specification/pull/383))\r\n* Feature to express details for component authors ([#335](https://github.com/CycloneDX/specification/issues/335) via [#379](https://github.com/CycloneDX/specification/pull/379))\r\n* Feature to express details for component and BOM manufacturer ([#346](https://github.com/CycloneDX/specification/issues/346) via [#379](https://github.com/CycloneDX/specification/pull/379))\r\n* Feature to express communicate concluded values from observed evidences ([#411](https://github.com/CycloneDX/specification/issues/411) via [#412](https://github.com/CycloneDX/specification/pull/412))\r\n* Features to express license acknowledgement ([#407](https://github.com/CycloneDX/specification/issues/407) via [#408](https://github.com/CycloneDX/specification/pull/408))\r\n* Feature to express environmental consideration information for model cards ([#396](https://github.com/CycloneDX/specification/issues/396) via [#395](https://github.com/CycloneDX/specification/pull/395))\r\n* Feature to express the address of organizational entities (via [#395](https://github.com/CycloneDX/specification/pull/395))\r\n* Feature to express additional component identifiers: Universal Bill Of Receipts Identifier and Software Heritage persistent IDs ([#413](https://github.com/CycloneDX/specification/issues/413) via [#414](https://github.com/CycloneDX/specification/pull/414))\r\n\r\n## Fixed\r\n\r\n* Allow multiple evidence identities by XML/JSON schema ([#272](https://github.com/CycloneDX/specification/issues/272) via [#359](https://github.com/CycloneDX/specification/pull/359))    \r\n  This was already correct via ProtoBuff schema.\r\n* Prevent empty `license` entities by XML schema ([#288](https://github.com/CycloneDX/specification/issues/288) via [#292](https://github.com/CycloneDX/specification/pull/292))  \r\n  This was already correct in JSON/ProtoBuff schema.\r\n* Prevent empty or malformed `property` entities by JSON schema ([#371](https://github.com/CycloneDX/specification/issues/371) via [#375](https://github.com/CycloneDX/specification/pull/375))  \r\n  This was already correct in XML/ProtoBuff schema.\r\n* Allow multiple `licenses` in `Metadata` by ProtoBuff schema ([#264](https://github.com/CycloneDX/specification/issues/264) via [#401](https://github.com/CycloneDX/specification/pull/401))  \r\n  This was already correct in XML/JSON schema.\r\n\r\n## Changed\r\n\r\n* Allow arbitrary `$schema` values by JSON schema ([#402](https://github.com/CycloneDX/specification/issues/402) via [#403](https://github.com/CycloneDX/specification/pull/403))\r\n* Increased max length of `versionRange` (via [`3e01ce6`](https://github.com/CycloneDX/specification/commit/3e01ce62a1c75e732538fe7e591dabb57a601983))\r\n* Harmonized length of `version` (via [#417](https://github.com/CycloneDX/specification/pull/417))\r\n\r\n## Deprecated\r\n\r\n* Data model _Component_'s field `author` was deprecated. (via [#379](https://github.com/CycloneDX/specification/pull/379))\r\n  Use field `authors` or field `manufacturer` instead.\r\n* Data model _Metadata_'s field `manufacture` was deprecated. ([#346](https://github.com/CycloneDX/specification/issues/346) via [#379](https://github.com/CycloneDX/specification/pull/379))\r\n  Use _Metadata_'s field `component`'s field `manufacturer` instead. \r\n  - for XML: `/bom/metadata/component/manufacturer`\r\n  - for JSON: `$.metadata.component.manufacturer`\r\n  - for ProtoBuf: `Bom:metadata.component.manufacturer`\r\n\r\n## Documentation\r\n\r\n* Centralize version and version-range (via [#322](https://github.com/CycloneDX/specification/pull/322))\r\n* Streamlined SPDX expression related descriptions (via [#327](https://github.com/CycloneDX/specification/pull/327))\r\n* Enhanced descriptions of `bom-ref`/`refType` ([#336](https://github.com/CycloneDX/specification/issues/336) via [#344](https://github.com/CycloneDX/specification/pull/344))\r\n* Enhanced readability of enum documentation in JSON schema ([#361](https://github.com/CycloneDX/specification/issues/361) via [#362](https://github.com/CycloneDX/specification/pull/362))\r\n* Fixed typo \"compliment\" -> \"complement\" (via [#369](https://github.com/CycloneDX/specification/pull/369))\r\n* Added documentation for enum _ComponentScope_'s values in JSON schema ([#293](https://github.com/CycloneDX/specification/issues/293) via [`d92e58e`](https://github.com/CycloneDX/specification/commit/d92e58efe09a384ce1b68ff1b7808903feb26d38))  \r\n  Texts were taken from the existing ones in XML/ProtoBuff schema.\r\n* Added documentation for enum _TaskType_'s values ([#245](https://github.com/CycloneDX/specification/issues/245) via [#377](https://github.com/CycloneDX/specification/pull/377))\r\n* Improve documentation for data model _Metadata_'s field `licenses` ([#273](https://github.com/CycloneDX/specification/issues/273) via [#378](https://github.com/CycloneDX/specification/pull/378))\r\n* Added documentation for enum _MachineLearningApproachType_'s values ([#351](https://github.com/CycloneDX/specification/pull/351) via [#416](https://github.com/CycloneDX/specification/pull/416))\r\n* Rephrased some texts here and there.\r\n\r\n## Test data\r\n\r\n* Added test data for newly added use cases\r\n* Added quality assurance for our ProtoBuf schemas ([#384](https://github.com/CycloneDX/specification/issues/384) via [#385](https://github.com/CycloneDX/specification/pull/385))\r\n\r\n----\r\n\r\n## What's Changed\r\n* Add BOM types by @stevespringett in https://github.com/CycloneDX/specification/pull/259\r\n* adjust default values by @jkowalleck in https://github.com/CycloneDX/specification/pull/260\r\n* Fix test data, closes #294 by @tokcum in https://github.com/CycloneDX/specification/pull/295\r\n* Fix test data inconsistency regarding  dependency tree in `valid-service`  by @jkowalleck in https://github.com/CycloneDX/specification/pull/297\r\n* chore: add `@CycloneDX/core-team` as default reviewers by @jkowalleck in https://github.com/CycloneDX/specification/pull/298\r\n* Fix test data regarding base64-encoded contents by @tokcum in https://github.com/CycloneDX/specification/pull/299\r\n* Fix test data regarding base64-encoded contents by @jkowalleck in https://github.com/CycloneDX/specification/pull/300\r\n* Fix `bom-ref` in test data `valid-compositions` by @tokcum in https://github.com/CycloneDX/specification/pull/302\r\n* Fix `bom-ref` in test data `valid-compositions` by @jkowalleck in https://github.com/CycloneDX/specification/pull/304\r\n* Fix test data regarding invalid SPDX license ID by @tokcum in https://github.com/CycloneDX/specification/pull/305\r\n* Fix test data regarding invalid SPDX license ID by @jkowalleck in https://github.com/CycloneDX/specification/pull/306\r\n* chore: add dependabot for github actions by @jkowalleck in https://github.com/CycloneDX/specification/pull/314\r\n* chore(deps): bump actions/checkout from 2 to 4 by @dependabot in https://github.com/CycloneDX/specification/pull/315\r\n* chore(deps): bump actions/setup-python from 2 to 4 by @dependabot in https://github.com/CycloneDX/specification/pull/316\r\n* chore(deps): bump actions/upload-artifact from 2 to 3 by @dependabot in https://github.com/CycloneDX/specification/pull/317\r\n* chore(deps): bump actions/setup-java from 1 to 3 by @dependabot in https://github.com/CycloneDX/specification/pull/318\r\n* chore: optimize CI runs by @jkowalleck in https://github.com/CycloneDX/specification/pull/324\r\n* Merges detectionContext properties with component evidence by @bhess in https://github.com/CycloneDX/specification/pull/325\r\n* CBOM: merges relatedCryptoMaterial and key asset types by @bhess in https://github.com/CycloneDX/specification/pull/313\r\n* refactor: centralize version and version-range by @jkowalleck in https://github.com/CycloneDX/specification/pull/322\r\n* docs: improve SPDX expression docs by @jkowalleck in https://github.com/CycloneDX/specification/pull/327\r\n* chore(deps): bump actions/setup-node from 3 to 4 by @dependabot in https://github.com/CycloneDX/specification/pull/328\r\n* CBOM: adds 'parameterSetIdentifier' property, replacing 'variant' by @bhess in https://github.com/CycloneDX/specification/pull/339\r\n* Enhance descriptions of `bom-ref` by @andreas-hilti in https://github.com/CycloneDX/specification/pull/344\r\n* Review description fields of 'algorithmProperties' by @bhess in https://github.com/CycloneDX/specification/pull/350\r\n* chore(deps): bump actions/setup-java from 3 to 4 by @dependabot in https://github.com/CycloneDX/specification/pull/352\r\n* chore(deps): bump actions/setup-python from 4 to 5 by @dependabot in https://github.com/CycloneDX/specification/pull/355\r\n* tests: java tests run agsinst CDX1.5 by @jkowalleck in https://github.com/CycloneDX/specification/pull/356\r\n* Support for hybrids/combiners: add 'combiner' as primitive by @bhess in https://github.com/CycloneDX/specification/pull/353\r\n* ci: split workflows by @jkowalleck in https://github.com/CycloneDX/specification/pull/357\r\n* chore(deps): bump actions/upload-artifact from 3 to 4 by @dependabot in https://github.com/CycloneDX/specification/pull/358\r\n* Refactored JSON enum descriptions to use meta:enum by @stevespringett in https://github.com/CycloneDX/specification/pull/362\r\n* Add `source-distribution` element to `externalReferenceType` by @tsjensen in https://github.com/CycloneDX/specification/pull/269\r\n* 1.6 dev attestations by @jkowalleck in https://github.com/CycloneDX/specification/pull/348\r\n* Fixed evidence identity. Updated test cases by @stevespringett in https://github.com/CycloneDX/specification/pull/359\r\n* rework dependency type to `provides` by @jkowalleck in https://github.com/CycloneDX/specification/pull/366\r\n* 1.6 dev cbom by @jkowalleck in https://github.com/CycloneDX/specification/pull/347\r\n* docs: Tweak \"compliment\" to \"complement\" by @msymons in https://github.com/CycloneDX/specification/pull/369\r\n* fix #288 by @jkowalleck in https://github.com/CycloneDX/specification/pull/292\r\n* 1.6 dev fix properties json - fixes #371 by @jkowalleck in https://github.com/CycloneDX/specification/pull/375\r\n* fix: correcting title of `attestations[].map[].counterClaim` by @idunbarh in https://github.com/CycloneDX/specification/pull/374\r\n* Add  `meta:enum` descriptions for task types by @mrutkows in https://github.com/CycloneDX/specification/pull/377\r\n* docs: describe `$.metadata.licenses` by @jkowalleck in https://github.com/CycloneDX/specification/pull/378\r\n* Add tags support by @stevespringett in https://github.com/CycloneDX/specification/pull/383\r\n* feat: decouple metadata from its component by @jkowalleck in https://github.com/CycloneDX/specification/pull/379\r\n* feat: external reference type for RFC-9116 by @jkowalleck in https://github.com/CycloneDX/specification/pull/381\r\n* introduce QA pipeline for protobuf schemas by @jkowalleck in https://github.com/CycloneDX/specification/pull/385\r\n* add headers to `*.textproto` by @jkowalleck in https://github.com/CycloneDX/specification/pull/393\r\n* tests: add example for component scope by @jkowalleck in https://github.com/CycloneDX/specification/pull/389\r\n* docs: spelling and grammar checks by @prabhu in https://github.com/CycloneDX/specification/pull/397\r\n* docs: Spelling and grammar checks by @prabhu in https://github.com/CycloneDX/specification/pull/398\r\n* remove restriction on json's  `$schema` annotation by @jkowalleck in https://github.com/CycloneDX/specification/pull/403\r\n* fix: protobuf `Metadata.licenses` repeated by @jkowalleck in https://github.com/CycloneDX/specification/pull/401\r\n* docs: fix examples for `versionRange` according to VERS spec by @jkowalleck in https://github.com/CycloneDX/specification/pull/415\r\n* Added descriptions for ML learning types by @stevespringett in https://github.com/CycloneDX/specification/pull/416\r\n* 1.6 bump bufbuild buf 1.30.0 by @jkowalleck in https://github.com/CycloneDX/specification/pull/418\r\n* fix/harmonize version length by @jkowalleck in https://github.com/CycloneDX/specification/pull/417\r\n* Added support for concluded value. Updated test cases. by @stevespringett in https://github.com/CycloneDX/specification/pull/412\r\n* Added support for license acknowledgements by @stevespringett in https://github.com/CycloneDX/specification/pull/408\r\n* Propose new environmental consideration information for ML models by @mrutkows in https://github.com/CycloneDX/specification/pull/395\r\n* Add support for OmniBOR and Software Heritage persistent IDs by @stevespringett in https://github.com/CycloneDX/specification/pull/414\r\n* fix: revisit new component identifiers by @jkowalleck in https://github.com/CycloneDX/specification/pull/419\r\n* Updated dependency attribute docs by @prabhu in https://github.com/CycloneDX/specification/pull/421\r\n* v1.6  by @jkowalleck in https://github.com/CycloneDX/specification/pull/323\r\n\r\n## New Contributors\r\n* @tokcum made their first contribution in https://github.com/CycloneDX/specification/pull/295\r\n* @bhess made their first contribution in https://github.com/CycloneDX/specification/pull/325\r\n* @andreas-hilti made their first contribution in https://github.com/CycloneDX/specification/pull/344\r\n* @tsjensen made their first contribution in https://github.com/CycloneDX/specification/pull/269\r\n* @idunbarh made their first contribution in https://github.com/CycloneDX/specification/pull/374\r\n* @prabhu made their first contribution in https://github.com/CycloneDX/specification/pull/397\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.5...1.6","reactions":{"url":"https://api.github.com/repos/CycloneDX/specification/releases/150328245/reactions","total_count":13,"+1":4,"-1":0,"laugh":0,"hooray":5,"confused":0,"heart":2,"rocket":2,"eyes":0},"mentions_count":11},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/109843755","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/109843755/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/109843755/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.5","id":109843755,"author":{"login":"stevespringett","id":3878933,"node_id":"MDQ6VXNlcjM4Nzg5MzM=","avatar_url":"https://avatars.githubusercontent.com/u/3878933?v=4","gravatar_id":"","url":"https://api.github.com/users/stevespringett","html_url":"https://github.com/stevespringett","followers_url":"https://api.github.com/users/stevespringett/followers","following_url":"https://api.github.com/users/stevespringett/following{/other_user}","gists_url":"https://api.github.com/users/stevespringett/gists{/gist_id}","starred_url":"https://api.github.com/users/stevespringett/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/stevespringett/subscriptions","organizations_url":"https://api.github.com/users/stevespringett/orgs","repos_url":"https://api.github.com/users/stevespringett/repos","events_url":"https://api.github.com/users/stevespringett/events{/privacy}","received_events_url":"https://api.github.com/users/stevespringett/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4GjBUr","tag_name":"1.5","target_commitish":"master","name":"1.5","draft":false,"immutable":false,"prerelease":false,"created_at":"2023-06-26T02:44:27Z","updated_at":"2024-04-09T07:05:43Z","published_at":"2023-06-26T02:46:47Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.5","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.5","body":"Added Machine Learning  Bill of Materials (ML-BOM), Formulation (MBOM), Lifecycles, Identity Evidence, Annotations, and Low-code/no-code application support. And much more.\r\n\r\n**Announcement**: <https://cyclonedx.org/news/cyclonedx-v1.5-released/>\r\n\r\n----\r\n\r\n## What's Changed\r\n* Preserve  keys, but fix potential JSON pointers to reflect actual DOM… by @mrutkows in https://github.com/CycloneDX/specification/pull/125\r\n* add GH-workflow: php ci by @jkowalleck in https://github.com/CycloneDX/specification/pull/110\r\n* fix CWEs example by @kabo in https://github.com/CycloneDX/specification/pull/144\r\n* Fix invalid ref in tools/src/test/resources/1.4/valid-vulnerability-1.4.json by @damiencarol in https://github.com/CycloneDX/specification/pull/127\r\n* fix: add missing `Vulnerability.properties` types in schema 1.4 by @desenna in https://github.com/CycloneDX/specification/pull/148\r\n* Update Description by @msymons in https://github.com/CycloneDX/specification/pull/172\r\n* Added firstIssued and lastUpdated timestamps to vulnerability analysis by @stevespringett in https://github.com/CycloneDX/specification/pull/176\r\n* Resolves #130 - missing BOM properties in JSON and protobuf schemas by @stevespringett in https://github.com/CycloneDX/specification/pull/170\r\n* Add licensing support and unit tests by @stevespringett in https://github.com/CycloneDX/specification/pull/175\r\n* Added property support to license along with unit tests by @stevespringett in https://github.com/CycloneDX/specification/pull/177\r\n* Add annotations support and valid test cases by @stevespringett in https://github.com/CycloneDX/specification/pull/169\r\n* Adding support for security contact by @stevespringett in https://github.com/CycloneDX/specification/pull/180\r\n* Adding support vulnerability rejected timestamp along with unit tests by @stevespringett in https://github.com/CycloneDX/specification/pull/181\r\n* Added additional external references by @stevespringett in https://github.com/CycloneDX/specification/pull/189\r\n* Added device driver component type by @stevespringett in https://github.com/CycloneDX/specification/pull/190\r\n* Extend service dataflow support by @stevespringett in https://github.com/CycloneDX/specification/pull/194\r\n* Added support for CVSSv4 by @stevespringett in https://github.com/CycloneDX/specification/pull/195\r\n* Deprecated tool in favor of components and services used as tools by @stevespringett in https://github.com/CycloneDX/specification/pull/198\r\n* Added identity and occurrences to evidence. Updated test cases. by @stevespringett in https://github.com/CycloneDX/specification/pull/199\r\n* Add proof of concept support to vulnerability by @stevespringett in https://github.com/CycloneDX/specification/pull/200\r\n* fix `vulnerability.affects[].versions[].range` ref by @jkowalleck in https://github.com/CycloneDX/specification/pull/219\r\n* fix `vulnerability.affects[].versions[].range` ref by @jkowalleck in https://github.com/CycloneDX/specification/pull/218\r\n* Added support for ML by @stevespringett in https://github.com/CycloneDX/specification/pull/209\r\n* hint for device properties by @jkowalleck in https://github.com/CycloneDX/specification/pull/221\r\n* hint for device properties by @jkowalleck in https://github.com/CycloneDX/specification/pull/220\r\n* Added additional compositions and identity by @stevespringett in https://github.com/CycloneDX/specification/pull/212\r\n* Added lifecycle support by @stevespringett in https://github.com/CycloneDX/specification/pull/213\r\n* Adding external reference support for adversary model and risk assessment by @stevespringett in https://github.com/CycloneDX/specification/pull/215\r\n* fix JSON schema issues found by AJV by @jkowalleck in https://github.com/CycloneDX/specification/pull/230\r\n* `licenseChoice` streamlined by @jkowalleck in https://github.com/CycloneDX/specification/pull/205\r\n* fix: XML schema 1.4 make all `ref` arguments `type=\"bom:refType\"` by @jkowalleck in https://github.com/CycloneDX/specification/pull/183\r\n* schema: own type for `ref`/`bom-ref` by @jkowalleck in https://github.com/CycloneDX/specification/pull/115\r\n* Fixing missing data governance on service data by @stevespringett in https://github.com/CycloneDX/specification/pull/234\r\n* Introduce type for BOM-Link by @jkowalleck in https://github.com/CycloneDX/specification/pull/235\r\n* Added poam as external reference type by @stevespringett in https://github.com/CycloneDX/specification/pull/227\r\n* Added bom-refs to organizationalEntity and organizationalContact by @stevespringett in https://github.com/CycloneDX/specification/pull/228\r\n* schema validate VS test data - php by @jkowalleck in https://github.com/CycloneDX/specification/pull/237\r\n* v1.5 validate XML/JSON test-data against schema - php by @jkowalleck in https://github.com/CycloneDX/specification/pull/238\r\n* fixed test data by @jkowalleck in https://github.com/CycloneDX/specification/pull/239\r\n* v1.5 fixed test data by @jkowalleck in https://github.com/CycloneDX/specification/pull/240\r\n* validate JSON test data against schema - JS by @jkowalleck in https://github.com/CycloneDX/specification/pull/241\r\n* Add SSVC to existing rating methods by @stevespringett in https://github.com/CycloneDX/specification/pull/224\r\n* Added formulation support and test cases by @stevespringett in https://github.com/CycloneDX/specification/pull/222\r\n* intro to explicitly linked elements by @jkowalleck in https://github.com/CycloneDX/specification/pull/236\r\n* V1.5 dev resourceReferenceChoice ref clarifications by @jkowalleck in https://github.com/CycloneDX/specification/pull/251\r\n* V1.5  JSON: fix `oneOf` documentations by @jkowalleck in https://github.com/CycloneDX/specification/pull/258\r\n* v1.5 complete linkable licenses by @jkowalleck in https://github.com/CycloneDX/specification/pull/252\r\n* streamline VulnerabilityReference by @jkowalleck in https://github.com/CycloneDX/specification/pull/253\r\n* [WIP] finalize 1.5 by @jkowalleck in https://github.com/CycloneDX/specification/pull/231\r\n\r\n## New Contributors\r\n* @kabo made their first contribution in https://github.com/CycloneDX/specification/pull/144\r\n* @damiencarol made their first contribution in https://github.com/CycloneDX/specification/pull/127\r\n* @desenna made their first contribution in https://github.com/CycloneDX/specification/pull/148\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.4...1.5","reactions":{"url":"https://api.github.com/repos/CycloneDX/specification/releases/109843755/reactions","total_count":6,"+1":2,"-1":0,"laugh":0,"hooray":4,"confused":0,"heart":0,"rocket":0,"eyes":0},"mentions_count":7},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/56923484","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/56923484/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/56923484/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.4","id":56923484,"author":{"login":"stevespringett","id":3878933,"node_id":"MDQ6VXNlcjM4Nzg5MzM=","avatar_url":"https://avatars.githubusercontent.com/u/3878933?v=4","gravatar_id":"","url":"https://api.github.com/users/stevespringett","html_url":"https://github.com/stevespringett","followers_url":"https://api.github.com/users/stevespringett/followers","following_url":"https://api.github.com/users/stevespringett/following{/other_user}","gists_url":"https://api.github.com/users/stevespringett/gists{/gist_id}","starred_url":"https://api.github.com/users/stevespringett/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/stevespringett/subscriptions","organizations_url":"https://api.github.com/users/stevespringett/orgs","repos_url":"https://api.github.com/users/stevespringett/repos","events_url":"https://api.github.com/users/stevespringett/events{/privacy}","received_events_url":"https://api.github.com/users/stevespringett/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBYZ-Wc4DZJVc","tag_name":"1.4","target_commitish":"master","name":"1.4","draft":false,"immutable":false,"prerelease":false,"created_at":"2022-01-12T14:09:53Z","updated_at":"2024-04-09T07:06:17Z","published_at":"2022-01-12T14:11:40Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.4","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.4","body":"Added support for Vulnerability Exploitability Exchange (VEX), a standard release notes format, improved hardware device support and many other small improvements.\r\n\r\n**Announcement**: <https://cyclonedx.org/news/cyclonedx-v1.4-released/>\r\n\r\n----\r\n\r\n## What's Changed\r\n* Added external references support to tools by @stevespringett in https://github.com/CycloneDX/specification/pull/102\r\n* Made component version optional by @stevespringett in https://github.com/CycloneDX/specification/pull/92\r\n* Added vulnerabilities as part of core spec by @stevespringett in https://github.com/CycloneDX/specification/pull/91\r\n* Implemented release notes in XML, JSON, and Protobuf by @stevespringett in https://github.com/CycloneDX/specification/pull/88\r\n* Implemented JSF in the core spec by @stevespringett in https://github.com/CycloneDX/specification/pull/93\r\n* JSON strict: add optional root property `$schema` by @jkowalleck in https://github.com/CycloneDX/specification/pull/107\r\n* spec1.4 JSON fixes #83 by @jkowalleck in https://github.com/CycloneDX/specification/pull/109\r\n* spec 1.4 JSON schema: remove unnecessary self-shadowing `$id` by @jkowalleck in https://github.com/CycloneDX/specification/pull/111\r\n* schema spec1.4: own type for `ref`/`bom-ref` by @jkowalleck in https://github.com/CycloneDX/specification/pull/116\r\n* spec1.4 JSON schema : bugfixes  #83 by @jkowalleck in https://github.com/CycloneDX/specification/pull/117\r\n* Add service release notes to v1.4 proto file by @coderpatros in https://github.com/CycloneDX/specification/pull/120\r\n* v1.4 General Availability by @stevespringett in https://github.com/CycloneDX/specification/pull/121\r\n\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.3...1.4","reactions":{"url":"https://api.github.com/repos/CycloneDX/specification/releases/56923484/reactions","total_count":6,"+1":3,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":3,"eyes":0},"mentions_count":3},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/42445447","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/42445447/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/42445447/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.3","id":42445447,"author":{"login":"stevespringett","id":3878933,"node_id":"MDQ6VXNlcjM4Nzg5MzM=","avatar_url":"https://avatars.githubusercontent.com/u/3878933?v=4","gravatar_id":"","url":"https://api.github.com/users/stevespringett","html_url":"https://github.com/stevespringett","followers_url":"https://api.github.com/users/stevespringett/followers","following_url":"https://api.github.com/users/stevespringett/following{/other_user}","gists_url":"https://api.github.com/users/stevespringett/gists{/gist_id}","starred_url":"https://api.github.com/users/stevespringett/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/stevespringett/subscriptions","organizations_url":"https://api.github.com/users/stevespringett/orgs","repos_url":"https://api.github.com/users/stevespringett/repos","events_url":"https://api.github.com/users/stevespringett/events{/privacy}","received_events_url":"https://api.github.com/users/stevespringett/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"MDc6UmVsZWFzZTQyNDQ1NDQ3","tag_name":"1.3","target_commitish":"master","name":"1.3","draft":false,"immutable":false,"prerelease":false,"created_at":"2021-05-04T22:55:12Z","updated_at":"2024-04-09T07:06:53Z","published_at":"2021-05-04T22:56:19Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.3","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.3","body":"Implemented support for compositions which precisely describe the completeness of relationships (component assemblies and dependencies). Added name-value store that can be used to describe additional data about the components, services, or the SBOM that isn’t native to the core specification. Improved support for copyright holders and licenses as additional evidence. Added license support for the SBOM itself. Added support for Protocol Buffers to make machine to machine SBOM transport more efficient.\r\n\r\n**Announcement**: <https://cyclonedx.org/news/cyclonedx-v1.3-released/>\r\n\r\n----\r\n\r\n## What's Changed\r\n* Bump junit from 4.12 to 4.13.1 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/39\r\n* manufacture grammar fix by @bradh in https://github.com/CycloneDX/specification/pull/58\r\n* Add protobuf format by @coderpatros in https://github.com/CycloneDX/specification/pull/54\r\n* Add BOM license information by @coderpatros in https://github.com/CycloneDX/specification/pull/52\r\n* Added support for key/value store (properties) by @stevespringett in https://github.com/CycloneDX/specification/pull/55\r\n* Initial implementation for compositions (known unknowns) by @stevespringett in https://github.com/CycloneDX/specification/pull/59\r\n* Added support for evidence of licenses and copyrights by @stevespringett in https://github.com/CycloneDX/specification/pull/61\r\n* Refactor BOM license to make use of license choice type by @coderpatros in https://github.com/CycloneDX/specification/pull/65\r\n* Tracking updates to protobuf format for feedback by @coderpatros in https://github.com/CycloneDX/specification/pull/66\r\n* #69 - Added support for hashes on external references. Added unit tests by @stevespringett in https://github.com/CycloneDX/specification/pull/71\r\n* URI cleanup for JSON by @stevespringett in https://github.com/CycloneDX/specification/pull/68\r\n* Removed default empty string and unnecessary regex pattern by @stevespringett in https://github.com/CycloneDX/specification/pull/74\r\n* Fix a few places where uri-reference has been applied at the array level instead of the array item level by @coderpatros in https://github.com/CycloneDX/specification/pull/75\r\n* Specification v1.3 by @coderpatros in https://github.com/CycloneDX/specification/pull/63\r\n* v1.3 Release candidate - Removing snapshot in preparation for release by @stevespringett in https://github.com/CycloneDX/specification/pull/76\r\n* Bump commons-io from 2.5 to 2.7 in /tools by @dependabot in https://github.com/CycloneDX/specification/pull/64\r\n\r\n## New Contributors\r\n* @bradh made their first contribution in https://github.com/CycloneDX/specification/pull/58\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.2...1.3","reactions":{"url":"https://api.github.com/repos/CycloneDX/specification/releases/42445447/reactions","total_count":1,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":1,"eyes":0},"mentions_count":4},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/26917713","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/26917713/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/26917713/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.2","id":26917713,"author":{"login":"stevespringett","id":3878933,"node_id":"MDQ6VXNlcjM4Nzg5MzM=","avatar_url":"https://avatars.githubusercontent.com/u/3878933?v=4","gravatar_id":"","url":"https://api.github.com/users/stevespringett","html_url":"https://github.com/stevespringett","followers_url":"https://api.github.com/users/stevespringett/followers","following_url":"https://api.github.com/users/stevespringett/following{/other_user}","gists_url":"https://api.github.com/users/stevespringett/gists{/gist_id}","starred_url":"https://api.github.com/users/stevespringett/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/stevespringett/subscriptions","organizations_url":"https://api.github.com/users/stevespringett/orgs","repos_url":"https://api.github.com/users/stevespringett/repos","events_url":"https://api.github.com/users/stevespringett/events{/privacy}","received_events_url":"https://api.github.com/users/stevespringett/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"MDc6UmVsZWFzZTI2OTE3NzEz","tag_name":"1.2","target_commitish":"master","name":"1.2","draft":false,"immutable":false,"prerelease":false,"created_at":"2020-05-26T20:02:41Z","updated_at":"2024-04-09T06:32:03Z","published_at":"2020-05-26T20:35:07Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.2","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.2","body":"This release includes ‘firmware’ and ‘container’ component types, SWID tags, service components, applied patches, JSON support, and enhanced BOM metadata and dependency graphs previously only available through extensions.\r\n\r\n----\r\n\r\n## What's Changed\r\n* Draft vulnerability schema extension by @kakumara in https://github.com/CycloneDX/specification/pull/19\r\n* Delete CODE_OF_CONDUCT.md by @coderpatros in https://github.com/CycloneDX/specification/pull/25\r\n\r\n## New Contributors\r\n* @kakumara made their first contribution in https://github.com/CycloneDX/specification/pull/19\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.1...1.2","mentions_count":2},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/150333593","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/150333593/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/150333593/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.1","id":150333593,"author":{"login":"jkowalleck","id":2765863,"node_id":"MDQ6VXNlcjI3NjU4NjM=","avatar_url":"https://avatars.githubusercontent.com/u/2765863?v=4","gravatar_id":"","url":"https://api.github.com/users/jkowalleck","html_url":"https://github.com/jkowalleck","followers_url":"https://api.github.com/users/jkowalleck/followers","following_url":"https://api.github.com/users/jkowalleck/following{/other_user}","gists_url":"https://api.github.com/users/jkowalleck/gists{/gist_id}","starred_url":"https://api.github.com/users/jkowalleck/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jkowalleck/subscriptions","organizations_url":"https://api.github.com/users/jkowalleck/orgs","repos_url":"https://api.github.com/users/jkowalleck/repos","events_url":"https://api.github.com/users/jkowalleck/events{/privacy}","received_events_url":"https://api.github.com/users/jkowalleck/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"MDc6UmVsZWFzZTE1MDMzMzU5Mw==","tag_name":"1.1","target_commitish":"master","name":"1.1","draft":false,"immutable":false,"prerelease":false,"created_at":"2019-10-24T17:09:21Z","updated_at":"2024-04-09T06:36:15Z","published_at":"2024-04-09T06:33:27Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.1","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.1","body":"CycloneDX 1.1  —  03 March 2019\r\n\r\n----\r\n\r\n**Full Changelog**: https://github.com/CycloneDX/specification/compare/1.0...1.1"},{"url":"https://api.github.com/repos/CycloneDX/specification/releases/150333723","assets_url":"https://api.github.com/repos/CycloneDX/specification/releases/150333723/assets","upload_url":"https://uploads.github.com/repos/CycloneDX/specification/releases/150333723/assets{?name,label}","html_url":"https://github.com/CycloneDX/specification/releases/tag/1.0","id":150333723,"author":{"login":"jkowalleck","id":2765863,"node_id":"MDQ6VXNlcjI3NjU4NjM=","avatar_url":"https://avatars.githubusercontent.com/u/2765863?v=4","gravatar_id":"","url":"https://api.github.com/users/jkowalleck","html_url":"https://github.com/jkowalleck","followers_url":"https://api.github.com/users/jkowalleck/followers","following_url":"https://api.github.com/users/jkowalleck/following{/other_user}","gists_url":"https://api.github.com/users/jkowalleck/gists{/gist_id}","starred_url":"https://api.github.com/users/jkowalleck/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jkowalleck/subscriptions","organizations_url":"https://api.github.com/users/jkowalleck/orgs","repos_url":"https://api.github.com/users/jkowalleck/repos","events_url":"https://api.github.com/users/jkowalleck/events{/privacy}","received_events_url":"https://api.github.com/users/jkowalleck/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"MDc6UmVsZWFzZTE1MDMzMzcyMw==","tag_name":"1.0","target_commitish":"master","name":"1.0","draft":false,"immutable":false,"prerelease":false,"created_at":"2018-03-26T23:13:29Z","updated_at":"2024-04-09T06:36:31Z","published_at":"2024-04-09T06:34:27Z","assets":[],"tarball_url":"https://api.github.com/repos/CycloneDX/specification/tarball/1.0","zipball_url":"https://api.github.com/repos/CycloneDX/specification/zipball/1.0","body":"CycloneDX 1.0  — 26 March 2018"}]