Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Definition of product #692

Open
wurstbrot opened this issue Feb 19, 2024 · 2 comments
Open

Definition of product #692

wurstbrot opened this issue Feb 19, 2024 · 2 comments

Comments

@wurstbrot
Copy link

Hi,

the product in CSAF might only be a library. Therefore, I feel it should be named component. Which is more generic.

As product is used a lot, a renaming might not be (easily) possible. Therefore, I recommend to update the definition from

product: is any deliverable (e.g. software, hardware, specification,...) which can be referred to with a name. This applies regardless of the origin, the license model, or the mode of distribution of the deliverable.

to:

product: is any deliverable (e.g. software, software libraries, hardware, specification,...) which can be referred to with a name. This applies regardless of the origin, the license model, or the mode of distribution of the deliverable.

Depending on the definition of software, you can argue library is included, already. But to point it out would be good because I thought it is an application until digging deeper in the CSAF specification.

@tschmidtb51
Copy link
Contributor

@wurstbrot Thank you for your contribution.

As "a product is defined as any deliverable which can be referred to with a name", I don't think that component would be a good fit. Would you for example refer to ISO 27001 as component? To me, a component is a part - so renaming might confuse other people who then ask where to put their final products...

Nevertheless, the TC will consider you suggestion.

@wurstbrot
Copy link
Author

I agree that component wouldn't match and product is sufficient.

I personally, taking your comment into account, would call it artifact (which is a bit more technical and commonly used in software development and engineering contexts).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants