From 968b901a0af179d7e88255555d2cd430d65245ff Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 16 Sep 2026 14:32:57 +0200 Subject: [PATCH 1/2] chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#1103) Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/zizmor.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml index 8e3ee8ea..0413c034 100644 --- a/.github/workflows/zizmor.yml +++ b/.github/workflows/zizmor.yml @@ -30,7 +30,7 @@ jobs: persist-credentials: false - name: Run zizmor 🌈 # see https://github.com/zizmorcore/zizmor-action - uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 + uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3 with: # advanced-security: false => emit findings as workflow-command annotations (::error file=…) rather than # uploading a SARIF report to GitHub's Security tab. From 2872084eb3202f2da77ab03a40fcb0ed6d0185ba Mon Sep 17 00:00:00 2001 From: Quentin Kaiser <569494+qkaiser@users.noreply.github.com> Date: Wed, 16 Sep 2026 15:04:13 +0200 Subject: [PATCH 2/2] fix(xml): allow protocol cryptographic relationships (#1019) Signed-off-by: Quentin Kaiser Signed-off-by: Jan Kowalleck Co-authored-by: Jan Kowalleck --- schema/bom-1.7.xsd | 42 ++++++++++++++++++- .../1.7/valid-cryptography-full-1.7.json | 8 +++- .../1.7/valid-cryptography-full-1.7.textproto | 6 +++ .../1.7/valid-cryptography-full-1.7.xml | 6 +++ 4 files changed, 60 insertions(+), 2 deletions(-) diff --git a/schema/bom-1.7.xsd b/schema/bom-1.7.xsd index 59111cba..3d0a3564 100644 --- a/schema/bom-1.7.xsd +++ b/schema/bom-1.7.xsd @@ -8295,8 +8295,48 @@ limitations under the License. - A protocol-related cryptographic assets + + DEPRECATED - DO NOT USE. This will be removed in a future version. Use `./relatedCryptographicAssets` instead. + A protocol-related cryptographic asset. + + + + + + + A list of cryptographic assets related to this component. + + + + + + + A cryptographic asset related to this component. + + + + + + + + Specifies the mechanism by which the cryptographic asset is secured by. + Examples: "publicKey", "privateKey", "algorithm" + + + + + + + The bom-ref to cryptographic asset. + + + + + + + + diff --git a/tools/src/test/resources/1.7/valid-cryptography-full-1.7.json b/tools/src/test/resources/1.7/valid-cryptography-full-1.7.json index d03b237e..a12f9eb1 100644 --- a/tools/src/test/resources/1.7/valid-cryptography-full-1.7.json +++ b/tools/src/test/resources/1.7/valid-cryptography-full-1.7.json @@ -239,7 +239,13 @@ "algorithm": "ecdsa_secp256r1_sha256" } ] - } + }, + "relatedCryptographicAssets": [ + { + "type": "publicKey", + "ref": "asset-4" + } + ] }, "oid": "oid:1.3.6.1.5.5.7.3.1" } diff --git a/tools/src/test/resources/1.7/valid-cryptography-full-1.7.textproto b/tools/src/test/resources/1.7/valid-cryptography-full-1.7.textproto index 3552caf6..94909e43 100644 --- a/tools/src/test/resources/1.7/valid-cryptography-full-1.7.textproto +++ b/tools/src/test/resources/1.7/valid-cryptography-full-1.7.textproto @@ -231,6 +231,12 @@ components: { algorithm: "ecdsa_secp256r1_sha256" } } + relatedCryptographicAssets: { + assets: { + type: "publicKey" + ref: "asset-4" + } + } } oid: "oid:1.3.6.1.5.5.7.3.1" } diff --git a/tools/src/test/resources/1.7/valid-cryptography-full-1.7.xml b/tools/src/test/resources/1.7/valid-cryptography-full-1.7.xml index 7201e741..4685de3c 100644 --- a/tools/src/test/resources/1.7/valid-cryptography-full-1.7.xml +++ b/tools/src/test/resources/1.7/valid-cryptography-full-1.7.xml @@ -220,6 +220,12 @@ ecdsa_secp256r1_sha256 + + + publicKey + asset-4 + + oid:1.3.6.1.5.5.7.3.1