Skip to content

[pull] master from CycloneDX:master#7

Open
pull[bot] wants to merge 138 commits intofahedouch:masterfrom
CycloneDX:master
Open

[pull] master from CycloneDX:master#7
pull[bot] wants to merge 138 commits intofahedouch:masterfrom
CycloneDX:master

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Feb 9, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

jkowalleck and others added 19 commits October 2, 2025 16:50
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Closes #785

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Add Argon2 (RFC 9106) to the Cryptography Registry with a parameterized pattern aligned to RFC terminology.

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Add CTR_DRBG, Hash_DRBG, and HMAC_DRBG entries with NIST SP800-90Ar1 reference.

Closes #789

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
…nd Argon2 pattern inputs per RFC 9106

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
…806)

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Corrects a typo in Protocol Buffers schema documentation: "plan text" ->
"plain text" for the example.

Closes #785.
fixes #186


this automation will do the following on a daily/scheduled basis
- auto-detect the latest release of SPDX licenses
- update OUR list of known SPDX licenses
- Pull request the changes, if needed
@pull pull bot locked and limited conversation to collaborators Feb 9, 2026
@pull pull bot added the ⤵️ pull label Feb 9, 2026
Mehrn0ush and others added 9 commits February 12, 2026 14:31
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Joachim Vandersmissen <git@jvdsn.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrnoush <mehrnoush.vaseghi@gmail.com>
Add SRP (RFC2945/RFC5054) and J-PAKE (RFC8236) key agreement entries.

Closes #791

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Keep cryptography-defs.schema.json aligned with cryptography-defs.json.

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Refs #787

Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
Signed-off-by: Mehrn0ush <mehrnoush.vaseghi@gmail.com>
jkowalleck and others added 30 commits March 13, 2026 15:46
fixes/streamlines XML docs behavior when loading an anchor.

example: https://cyclonedx.org/docs/1.7/xml/#Glossary
Adds AES-OCB to the cryptography registry under the AES family.

Details:
- Primitive: `ae`
- Pattern: `AES[-(128|192|256)]-OCB[-{tagLength}]`
- Standard: RFC 7253



Fixes #884
Changes the SipHash registry entry to classify it as `mac` instead of
`hash`, and updates the reference URL to an archival source.


Fixes #882
Removes duplicate `MD4` and `MD5` family entries from the cryptography
registry.

Fixes #878
The official name of the hash algorithms does not contain the dash.
According to RFC8032, the names are Ed25519ph, Ed25519ctx, and Ed448ph.
There is no dash.
fixes #872 

Also changes primitive to "kdf" since this is a KDF, not a key agreement
function.
Also add some missing standards to AES, partially fixes #834
Fixes #874

The additional distinction for RFC7627 is to distinguish between usage
of the extended master secret and not.
Signed-off-by: Steve Springett <steve@springett.us>
Fixed missing comma in JSON
Signed-off-by: Joachim Vandersmissen <git@jvdsn.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants