github.com/CycloneDX/sbom-utility@v0.16.0/test/custom/cdx-1-3-test-custom-invalid-composition-metadata-component.json (about) 1 { 2 "bomFormat": "CycloneDX", 3 "specVersion": "1.3", 4 "version": 1, 5 "serialNumber": "urn:uuid:1a2b3c4d-1234-abcd-9876-a3b4c5d6e7e0", 6 "metadata": { 7 "timestamp": "2021-04-14T07:20:00.000Z", 8 "component": { 9 "type": "application", 10 "bom-ref": "pkg:app/sample@2.0.0", 11 "purl": "pkg:app/sample@2.0.0", 12 "name": "sample app", 13 "version": "2.0.0", 14 "description": "Sample application", 15 "components": [ 16 { 17 "type": "library", 18 "bom-ref": "pkg:npm/bad-nest@1.0.0", 19 "purl": "pkg:npm/bad-nest@1.0.0", 20 "name": "bad nest", 21 "version": "1.0.0", 22 "description": "Bad nested library" 23 } 24 ] 25 } 26 }, 27 "components": [ 28 { 29 "type": "library", 30 "bom-ref": "pkg:npm/libraryA@1.0.0", 31 "purl": "pkg:npm/libraryA@1.0.0", 32 "name": "Library A", 33 "version": "1.0.0", 34 "description": "Library A description" 35 }, 36 { 37 "type": "library", 38 "bom-ref": "pkg:npm/libraryB@1.0.0", 39 "purl": "pkg:npm/libraryB@1.0.0", 40 "name": "Library B", 41 "version": "1.0.0", 42 "description": "Library B description." 43 } 44 ] 45 }