There are a few ways to take part, depending on what you want to do. Pick whichever fits — none of them requires editing files or using a command line.

Most common

Weigh in on an aspect

Open the Issues page, pick a topic, read from the top, and add your view in the comment box. A reaction emoji is a quick temperature check.

Go to issues ↗
Open-ended

Start a discussion

For a topic that hasn't narrowed to a single decision yet, open a Discussion. It can be promoted to an aspect issue once it's ready to converge.

Go to discussions ↗
By email

Suggest a reference

Spotted a standard, regulation or guidance we should track? Send a short note to the working-group mailing list — no GitHub account needed.

How to suggest one ↓
By email

Suggest a tool

Know software that produces, reads or checks CBOMs? Send a link to where its maintainer says so, and it can be added to the tooling registry.

How to suggest one ↓

Discuss the methodology

The methodology is built one aspect at a time, in the open. To take part:

We keep deliberation (issues and discussions), decisions (records in /decisions), and the artifact (the spec text, changed by pull request) deliberately separate, and we work by lazy consensus. The full lifecycle is in CONTRIBUTING.md.

Suggest a reference

The reference register is curated by the working group. You don’t edit it directly — instead, send the details to the CBOM mailing list and a maintainer will review the suggestion and fold it in.

Email: cbom@lists.pkic.org — subject line “CBOM reference suggestion”.

To make the suggestion easy to add, please include:

Email a reference suggestion ↗ See the register

Prefer GitHub? You can also open an issue on the repository with the same details — whichever is easier for you.

Suggest a tool

The tooling registry lists software that works with CBOMs. As with references, you don’t edit it directly: send the details to the mailing list and a maintainer will add it. Suggestions for your own organisation’s tools are welcome, and are held to the same rule as any other.

Email: cbom@lists.pkic.org — subject line “CBOM tool suggestion”.

Please include:

A listing is not an endorsement and is not a conformance result: the working group does not test the tools it lists.

Come to a meeting

The Meetings page lists what is coming up and what the group has already worked through. An upcoming meeting carries its agenda, so you can see whether a topic you care about is being taken before you decide to attend; a past one carries the recording where one was made, and the slides presented, which you can download.

Meetings are open to working group members — see the working group page for how to join. Nothing on this page other than this section needs a meeting: the aspects, the discussions and the reference suggestions all work asynchronously, and that is where most of the work happens.

Edit the specification (optional, later)

When there is draft specification text to improve, you can propose a change straight from the browser: open the file, click the pencil ✏️ icon, make your edit, and click Propose changes. GitHub turns it into a pull request for others to review — you never touch a command line.


For maintainers. The register is a single data file, docs/_data/references.yml. Mailing-list suggestions are vetted and added following the field definitions and house rules in CONTRIBUTING-references.md. Meetings and presentations work the same way, from docs/_data/meetings.yml and docs/_data/presentations.yml, under CONTRIBUTING-meetings.md. The tooling registry is docs/_data/tooling.yml, under CONTRIBUTING-tooling.md.