CBOMProfiles /Methodology ← Working group site
INTERACTIVE

Conformance evaluation

Four example documents, evaluated against the Interface Disclosure Baseline (loading…). The first declares both a service and a management interface and conforms. The second omits the management interface and fails a product rule. The third declares both but exercises each of the four disclosure outcomes. The fourth is a subject with no administrative surface at all, which satisfies the management-interface rule by saying so rather than by having one: a structural rule is satisfied by presence or by a stated absence, and silence is neither. The carrier version selector shows how the profile's declared acceptance range treats documents written to other versions of CycloneDX. Each of the four is a document committed alongside this page, and the rules come from the published rules file rather than a transcription of it. The results shown are tested against validate_cbom.py's on the same four documents, so this page and the reference tool cannot quietly disagree.

PASSvalue supplied and valid
HELDwithheld by the producer, permitted for this attribute
UNKNdeclared unknown to the producer
NONEundeclared: no value and no marker
FAILvalue supplied but invalid

The four outcomes are distinguished because they mean different things to a consumer. Withholding is a commercial position, an unknown is a limit of the producing process, and an undeclared attribute indicates the document was not built against the profile. Select the third example to see all four at once. See Challenges and the disclosure states in Profile.

Example document
Carrier version (CycloneDX specVersion)

Product-level rules (constraints on the set of interfaces)

    PKIC CBOM Profiles Working Group · illustrative documentation.