Skip to content

docs: add post-quantum migration CBOM example - #65

Draft
AAH20 wants to merge 1 commit into
CycloneDX:masterfrom
AAH20:codex/pqc-migration-cbom
Draft

AAH20 wants to merge 1 commit into
CycloneDX:masterfrom
AAH20:codex/pqc-migration-cbom

Conversation

@AAH20

@AAH20 AAH20 commented Aug 17, 2026

Copy link
Copy Markdown

Summary

Add a CycloneDX 1.7 CBOM example for an application in a staged post-quantum migration state.

The example represents ML-KEM-768 and ML-DSA-65 alongside classical ECDH P-256 and ECDSA P-256 assets. It separates the application, implementation library, and algorithm inventory with explicit dependsOn and provides relationships.

Closes #64.

Contents

  • a deterministic CycloneDX 1.7 JSON BOM
  • a minimal static source-discovery fixture containing no cryptographic material
  • interpretation guidance covering security levels, migration state, runtime uncertainty, and the limits of inventory evidence

The fixture is intentionally not a deployment recommendation. It does not claim that inventory presence proves implementation correctness, secure protocol negotiation, key management, or migration completion.

Validation

  • validated against the official CycloneDX 1.7 JSON schema and its referenced SPDX, JSF, and cryptography definition schemas
  • checked that all component bom-ref values are unique
  • checked that all dependsOn and provides references resolve
  • verified ML-KEM and ML-DSA object identifiers against the NIST Computer Security Objects Register
  • parsed the Python fixture successfully
Signed-off-by: aah20 <aah20@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant