From 4d527294e3b7e50a5db3c56071c93bcba0f5d53d Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 26 Aug 2026 11:28:06 +0200 Subject: [PATCH 01/10] Align docs between markdown and openapi spec for product release Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 9 +++++---- tea-product/tea-product-release.md | 25 +++++++++++++++---------- 2 files changed, 20 insertions(+), 14 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 8af8c76..e308a7e 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -118,7 +118,7 @@ paths: - name: uuid in: path required: true - description: UUID of TEA Product Release in the TEA server + description: Unique UUID of TEA Product Release in the TEA server schema: "$ref": "#/components/schemas/uuid" responses: @@ -1157,7 +1157,7 @@ components: type: string example: Apache Log4j 2 version: - description: Version number of the product release + description: Human-readable version string of the product release type: string example: 2.24.3 createdDate: @@ -1173,13 +1173,14 @@ components: May be disabled after the creation of the release object, but can't be enabled after creation of an object. identifiers: type: array - description: List of identifiers for the product release + description: | + Array of identifiers for the product release (idType: CPE/TEI/PURL; idValue: string) items: "$ref": "#/components/schemas/identifier" components: type: array description: | - List of component references that compose this product release. A component reference can optionally include + Array of component references that compose this product release. A component reference can optionally include the UUID of a specific component release to pin the exact version. items: "$ref": "#/components/schemas/component-ref" diff --git a/tea-product/tea-product-release.md b/tea-product/tea-product-release.md index 6097e50..0d6f51f 100644 --- a/tea-product/tea-product-release.md +++ b/tea-product/tea-product-release.md @@ -5,16 +5,19 @@ A TEA Product Release represents a specific versioned release of a TEA Product. It is the primary resolvable entity via TEI and the entry point for discovery of included components and related collections of security artefacts. Key attributes: -- uuid: Unique identifier of the product release -- product: UUID of the TEA Product this release belongs to -- version: Human-readable version string of the product release -- createdDate: Timestamp when the product release was created in TEA -- releaseDate: Upstream product release timestamp -- preRelease: Indicates pre-release/beta status -- identifiers: Array of identifiers (idType: CPE/TEI/PURL; idValue: string) -- components: Array of component references included in this product release - - uuid: UUID of the TEA Component - - release: Optional UUID of a specific component release to pin an exact version + +- __uuid__: A unique identifier for the TEA Product Release +- __product__: UUID of the TEA Product this release belongs to +- __version__: Human-readable version string of the product release +- __createdDate__: Timestamp when the product release was created in TEA (for sorting purposes) +- __releaseDate__: Timestamp of the product release +- __preRelease__: A flag indicating pre-release (or beta) status. May be disabled after the creation of the release object, but can't be enabled after creation of an object. (boolean) +- __identifiers__: Array of identifiers for the product release (idType: CPE/TEI/PURL; idValue: string) +- __components__: Array of component references that compose this product release. A component reference can optionally include the UUID of a specific component release to pin the exact version. + +Required fields: + +- uuid, version, createdDate, components Collections for a product release contain artefacts relevant to that product release. @@ -48,4 +51,6 @@ The following example is reused from the OpenAPI schema (`components/schemas/pro ``` Notes: + +- Property `product` exists in the schema and links a product release to its parent product; it may not be present in all examples. - Use uppercase idType values exactly as defined by the schema enum: CPE, TEI, PURL. From 1e49530865b1fc7fab1c10f799ddac969ff10b0c Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 26 Aug 2026 11:33:43 +0200 Subject: [PATCH 02/10] Alignment of TEA product object, removing old texts Signed-off-by: Olle E. Johansson --- tea-product/tea-product.md | 31 ++++++------------------------- 1 file changed, 6 insertions(+), 25 deletions(-) diff --git a/tea-product/tea-product.md b/tea-product/tea-product.md index a401309..5320cda 100644 --- a/tea-product/tea-product.md +++ b/tea-product/tea-product.md @@ -1,4 +1,4 @@ -# The TEA product API +# The TEA product object After TEA discovery, the [Transparency Exchange Identifier (TEI)](/discovery/readme.md) resolves to a specific TEA Product Release, which represents a concrete, versioned offering. A TEA Product is a higher-level object that groups multiple Product Releases for a product line or family and can be browsed via `/product/{uuid}/releases`. @@ -24,28 +24,21 @@ with the UUID of the TEA component. The reference list may also include a UUID of a specific release of a component in the case where a product always includes a single release of the component. -The URL can be to a different vendor or different site with the -same vendor. +The __TEA Product__ object groups multiple releases together. ## TEA Product object -A TEA Product object has the following parts: +Key attributes: - __uuid__: A unique identifier for the TEA product - __name__: Product name - __identifiers__: List of identifiers for the product - - __idType__: Type of identifier, e.g. `tei`, `purl`, `cpe` + - __idType__: Type of identifier, e.g. `TEI`, `PURL`, `CPE` - __idValue__: Identifier value -- __components__: List of TEA components for the product - - __uuid__: Unique identifier of the TEA component - - __release__: Optional UUID of a TEA component release -The TEA Component UUID is used in the Component API to find out which versions -of the Component that exists. +Required fields: -The goal of the TEA Product API is to provide a selection of product -versions to assist the user software in finding a match for the -owned version. +- uuid, name, identifiers ### Example @@ -91,15 +84,3 @@ for the version string. An automated system may want to provide the user with a GUI, listing versions and being able to scroll to the next page until the user selects a version. - -### Tea API operation - -* Recommendation: Support HTTP compression -* Recommendation: HTTP content negotiation - * Like "I prefer JSON, but can accept XML" -* Pagination support - * max per page - * start page - * Default value defined - - From bbd1cede91e828e48ba702ca26bc07c0112112f9 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 26 Aug 2026 11:44:30 +0200 Subject: [PATCH 03/10] Clarification of time stamp, adding EU declaration of conformity (CE) Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index e308a7e..43d3ad3 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1053,7 +1053,7 @@ components: description: URI of a human-readable web page with information about the error. identifier: type: object - description: An identifier with a specified type + description: An identifier of the component with a specified type properties: idType: description: Type of identifier, e.g. `TEI`, `PURL`, `CPE` @@ -1098,6 +1098,7 @@ components: - TISAX - CYBER_ESSENTIALS - CYBER_ESSENTIALS_PLUS + - EU_DECLARATION_OF_CONFORMITY uuid: type: string description: A UUID in lower case (RFC 9562) From 895303429d3e0aae894e9f4798fd37b5b830f8bc Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 26 Aug 2026 11:49:53 +0200 Subject: [PATCH 04/10] Moving PreRelease doc to product release Signed-off-by: Olle E. Johansson --- tea-component/tea-component.md | 30 ++++++++++-------------------- tea-product/tea-product-release.md | 17 +++++++++++++++-- 2 files changed, 25 insertions(+), 22 deletions(-) diff --git a/tea-component/tea-component.md b/tea-component/tea-component.md index 1d03d42..be28afb 100644 --- a/tea-component/tea-component.md +++ b/tea-component/tea-component.md @@ -1,18 +1,19 @@ -# The TEA Component API +# The TEA Component object The TEA Component represents a component lineage. A product release may be constructed with one or multiple TEA Components, each with their own set of -releases and related artefacts. +releases and related artefacts. The component has releases, which has a set +of artifacts for each release. One artifact may belong to multiple releases. Each TEA Component has a list of Component Releases (see `/component/{uuid}/releases`), which enumerates all known versions for that component. -The API should be very agnostic as to how a "version" is indicated - semver, vers, +The TEA API is agnostic as to how a "version" is indicated - semver, vers, name, hash or anything else. ## Versions and TEIs -Each product object has one or multiple TEI URLs. +Each product release and product object has one or multiple TEI URLs. For the API to be able to present a list of versions in a cronological order, a timestamp for a release is required. @@ -24,11 +25,12 @@ A TEA Component object has the following parts: - __uuid__: A unique identifier for the TEA component - __name__: Component name - __identifiers__: List of identifiers for the component - - __idType__: Type of identifier, e.g. `tei`, `purl`, `cpe` + - __idType__: Type of identifier, e.g. `TEI`, `PURL`, `CPE` - __idValue__: Identifier value -Note: In coming versions, there may be a flag indicating lifecycle status -for a component. +Required fields: + +- uuid, name, identifiers ### Examples @@ -64,19 +66,7 @@ Some examples of Maven artefacts as TEA Components: } ``` -## Handling the Pre-Release flag - -The "Pre-release" flag is used to indicate that this is not a final release. -For a given Component with a UUID, the flag can be set to indicate a "test", "beta", "alpha" -or similar non-deployed release. It can only be set when creating the Component. -The TEA implementation may allow it to be unset (False) once. This is to support -situations where a object is promoted as is after testing to production version. The flag can not -be set after initial creation and publication of the Component. - -If the final version is different from the pre-release (bugs fixed, code changed, different binary) -a new Component with a new UUID and version needs to be created. - ## References - Semantic versioning (Semver): -- PURL VERS +- VERS diff --git a/tea-product/tea-product-release.md b/tea-product/tea-product-release.md index 0d6f51f..b7b69af 100644 --- a/tea-product/tea-product-release.md +++ b/tea-product/tea-product-release.md @@ -1,4 +1,4 @@ -# TEA Product Release +# TEA Product Release object ## Overview @@ -50,7 +50,20 @@ The following example is reused from the OpenAPI schema (`components/schemas/pro } ``` -Notes: +## Handling the Pre-Release flag + +The "Pre-release" flag is used to indicate that this is not a final release. +For a given Component with a UUID, the flag can be set to indicate a "test", "beta", "alpha" +or similar non-deployed release. It can only be set when creating the Component. +The TEA implementation may allow it to be unset (False) once. This is to support +situations where a object is promoted as is after testing to production version. The flag can not +be set after initial creation and publication of the Component. + +If the final version is different from the pre-release (bugs fixed, code changed, different binary) +a new Component with a new UUID and version needs to be created. + + +## Notes - Property `product` exists in the schema and links a product release to its parent product; it may not be present in all examples. - Use uppercase idType values exactly as defined by the schema enum: CPE, TEI, PURL. From b694882994a22fcfda1b7d9092867c5ffe5f9c68 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 26 Aug 2026 12:02:16 +0200 Subject: [PATCH 05/10] Align openapi spec with markdown docs - add release distribution object Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 4 +-- tea-component/tea-release.md | 57 +++++++++++++++++++++++++++++------- 2 files changed, 49 insertions(+), 12 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 43d3ad3..3b14898 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1277,7 +1277,7 @@ components: description: A TEA Component Release properties: uuid: - description: A unique identifier for the TEA Component Release + description: A unique identifier of the TEA Component Release "$ref": "#/components/schemas/uuid" component: description: UUID of the TEA Component this release belongs to @@ -1287,7 +1287,7 @@ components: type: string example: tomcat version: - description: Version number + description: Human-readable version string type: string example: 1.2.3 createdDate: diff --git a/tea-component/tea-release.md b/tea-component/tea-release.md index 35af4ac..1d771ab 100644 --- a/tea-component/tea-release.md +++ b/tea-component/tea-release.md @@ -1,19 +1,44 @@ -# TEA Component Release +# TEA Component Release Object ## Overview -A TEA Component Release represents a specific version of a TEA Component lineage. It is the concrete, versioned entity which has collections of security-related artefacts (SBOM, VDR/VEX, attestations, etc.). +A __TEA Component Release__ represents a specific version of a TEA Component lineage. It is the concrete, versioned entity which has collections of security-related artifacts (SBOM, VDR/VEX, attestations, etc.). Key attributes: -- uuid: Unique identifier of the component release -- component: UUID of the TEA Component this release belongs to -- version: Human-readable version string -- createdDate: Timestamp when the release was created in TEA -- releaseDate: Upstream release timestamp -- preRelease: Indicates pre-release/beta status -- identifiers: Array of identifiers (idType: CPE/TEI/PURL; idValue: string) -Collections for a release contain artefacts relevant to that specific release. +- __uuid__: Unique identifier of the TEA Component Release (uuid) +- __component__: UUID of the TEA Component this release belongs to +- __componentName__: Name of the TEA Component this release belongs to +- __version__: Human-readable version string +- __createdDate__: Timestamp when this Release was created in TEA (for sorting purposes) +- __releaseDate__: Timestamp of the release +- __preRelease__: A flag indicating pre-release (or beta) status. May be disabled after the creation of the release object, but can't be enabled after creation of an object. +- __identifiers__: Array of identifiers for the component +- __distributions__: List of different formats of this component release + +Collections for a release contain artifacts relevant to that specific release. + +Required fields: + +- uuid, version, createdDate + +## TEA component release distribution object + +Distribution are object to declare different distribution formats of a component, +like source code or a package for a specific Linux distribution or a CPU type + +Key attributes: + +- __distributionId__: A unique identifier for the TEA Distribution object (uuid) +- __description__: Free-text description of the distribution. +- __identifiers__: Array of identifiers for the distribution of the release +- __url__: Direct download URL for the distribution +- __signatureUrl__: Direct download URL for the distribution's detached signature +- __checksums__: Array of checksums for the distribution + +Required fields: + +- distributionId ## JSON examples @@ -63,6 +88,18 @@ The following examples are reused from the OpenAPI schema (`components/schemas/r ] } ``` +## Handling the Pre-Release flag + +The "Pre-release" flag is used to indicate that this is not a final release. +For a given Component with a UUID, the flag can be set to indicate a "test", "beta", "alpha" +or similar non-deployed release. It can only be set when creating the Component. +The TEA implementation may allow it to be unset (False) once. This is to support +situations where a object is promoted as is after testing to production version. The flag can not +be set after initial creation and publication of the Component. + +If the final version is different from the pre-release (bugs fixed, code changed, different binary) +a new Component with a new UUID and version needs to be created. + Notes: - Use uppercase idType values exactly as defined by the schema enum: CPE, TEI, PURL. From 5a10f72d311d888c6cafce77418bea504d26d250 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 26 Aug 2026 12:07:11 +0200 Subject: [PATCH 06/10] Removing duplicated text, cleaning up Signed-off-by: Olle E. Johansson --- tea-collection/tea-collection.md | 273 +------------------------------ tea-component/tea-release.md | 251 +++++++++++++++++++++++++++- 2 files changed, 244 insertions(+), 280 deletions(-) diff --git a/tea-collection/tea-collection.md b/tea-collection/tea-collection.md index ab2ec28..dcff355 100644 --- a/tea-collection/tea-collection.md +++ b/tea-collection/tea-collection.md @@ -1,275 +1,4 @@ -# TEA Releases and Collections - -## The TEA Component Release object (TRO) - -A TEA Component Release object represents a specific version of a component, -identified by a unique version number and associated metadata. -Each release may include multiple distributions, -which capture variations such as architecture, packaging, or localization. - -- For software components, - each distribution typically corresponds to a different digital file delivered to users - (e.g., by platform or packaging type). -- For hardware components, distributions may reflect differences in packaging, language, or other physical attributes. - -Each distribution is assigned a unique `distributionType`, defined by the producer, -which is used to associate relevant TEA Artifacts with that distribution. -Since TEA Artifacts can be associated with multiple release objects, -the taxonomy for `distributionType` values should be defined on a TEA service level -and consistently applied to all TEA Artifacts published by that producer. -This ensures global uniqueness and reliable association across releases. - -The `uuid` of the TEA Component Release object is identical to the `uuid` of its associated -[TEA Collection object (TCO)](#the-tea-collection-object-tco). - -### Structure - -A TEA Component Release object contains the following fields: - -- __uuid__: Unique identifier for the TEA Component Release. -- __version__: Version number of the release. -- __createdDate__: Timestamp when the release object was created. -- __releaseDate__: Timestamp of the actual release. -- __preRelease__: Boolean flag indicating if this is a pre-release (e.g., beta). - This flag can be disabled after creation, but not enabled. -- __identifiers__: List of identifiers for the component. -- __idType__: Type of identifier (e.g., `TEI`, `PURL`, `CPE`). -- __idValue__: Value of the identifier. -- __distributions__: List of release distributions, each with: - - __distributionType__: Unique identifier for the distribution type. - - __description__: Free-text description of the distribution. - - __identifiers__: List of identifiers specific to this distribution. - - __idType__: Type of identifier (e.g., `TEI`, `PURL`, `CPE`). - - __idValue__: Value of the identifier. - - __url__: Direct download URL for the distribution. - - __signatureUrl__: Direct download URL for the distribution's external signature. - - __checksums__: List of checksums for the distribution. - - __algType__: Checksum algorithm used. - - __algValue__: Checksum value. - -### Examples - -#### Single distribution - -This example shows a TEA Component Release for Apache Log4j Core, which is distributed as a single JAR file. -Even though there is only one distribution, -the `distributions` attribute is included to enable searching for the release by the SHA-256 checksum of the JAR. -This structure also allows for future extensibility if additional distributions are introduced. - -
- Example of simple release - -```json -{ - "uuid": "b1e2c3d4-5678-49ab-9cde-123456789abc", - "version": "2.24.3", - "createdDate": "2024-12-10T10:51:00Z", - "releaseDate": "2024-12-13T12:52:29Z", - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3" - } - ], - "distributions": [ - { - "distributionType": "jar", - "description": "Binary distribution", - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar" - } - ], - "checksums": [ - { - "algType": "SHA-256", - "algValue": "b1e2c3d4f5a67890b1e2c3d4f5a67890b1e2c3d4f5a67890b1e2c3d4f5a67890" - } - ], - "url": "https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3.jar", - "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3.jar.asc" - } - ] -} -``` -
- -#### Multiple distributions - -This is an example of a TEA Component Release for Apache Tomcat 11.0.7 binary distributions. -The example defines four distinct `distributionType`s, -which is essential not only for associating the correct SBOMs with each distribution, -but also for accurately tracking and reporting vulnerabilities that may affect only specific distributions. -For instance: - -- The `zip` and `tar.gz` distributions contain only Java JARs. -- The `windows-x64.zip` distribution additionally includes the - [Apache Procrun](https://commons.apache.org/proper/commons-daemon/procrun.html) binary, - which is specific to Windows and may introduce unique vulnerabilities. -- The `windows-x64.exe` distribution contains the same data as `windows-x64.zip`, - but is packaged as a self-extracting installer - created by the [Nullsoft Scriptable Install System](https://nsis.sourceforge.io/Main_Page). - -By defining separate `distributionType`s, -it becomes possible to precisely associate artefacts and vulnerability disclosures with the affected distributions, -ensuring accurate risk assessment and remediation. - -
- Example of four different binary distributions in the same release - -```json -{ - "uuid": "605d0ecb-1057-40e4-9abf-c400b10f0345", - "version": "11.0.7", - "createdDate": "2025-05-07T18:08:00Z", - "releaseDate": "2025-05-12T18:08:00Z", - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7" - } - ], - "distributions": [ - { - "distributionType": "zip", - "description": "Core binary distribution, zip archive", - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7?type=zip" - } - ], - "checksums": [ - { - "algType": "SHA_256", - "algValue": "9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1" - } - ], - "url": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip", - "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip.asc" - }, - { - "distributionType": "tar.gz", - "description": "Core binary distribution, tar.gz archive", - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7?type=tar.gz" - } - ], - "checksums": [ - { - "algType": "SHA_256", - "algValue": "2fcece641c62ba1f28e1d7b257493151fc44f161fb391015ee6a95fa71632fb9" - } - ], - "url": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.tar.gz", - "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.tar.gz.asc" - }, - { - "distributionType": "windows-x64.zip", - "description": "Core binary distribution, Windows x64 zip archive", - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7?classifier=windows-x64&type=zip" - } - ], - "checksums": [ - { - "algType": "SHA_256", - "algValue": "62a5c358d87a8ef21d7ec1b3b63c9bbb577453dda9c00cbb522b16cee6c23fc4" - } - ], - "url": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7-windows-x64.zip", - "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip.asc" - }, - { - "distributionType": "windows-x64.exe", - "description": "Core binary distribution, Windows Service Installer (MSI)", - "checksums": [ - { - "algType": "SHA_512", - "algValue": "1d3824e7643c8aba455ab0bd9e67b14a60f2aaa6aa7775116bce40eb0579e8ced162a4f828051d3b867e96ee2858ec5da0cc654e83a83ba30823cbea0df4ff96" - } - ], - "url": "https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe", - "signatureUrl": "https://downloads.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe.asc" - } - ] -} -``` -
- -#### Pre-release flag usage - -The `preRelease` flag is used to indicate that a release is not production ready, -regardless of the version naming scheme. -This helps consumers identify non-production releases without relying on conventions like `-beta`, -`-rc`, or `-M` in the version string. - -There are two main scenarios for using the `preRelease` flag: - -- **Pending release:** The distribution is still undergoing quality assurance or review and is not yet officially released. - These typically lack a `releaseDate` attribute. - Once the release is approved, the `preRelease` flag is set to `false` and the `releaseDate` is added. -- **Permanent pre-release:** The distribution is intentionally marked as a pre-release - (e.g., beta, milestone, or release candidate) and will never be considered production ready, - even after all checks are complete. - These may have a `releaseDate`, but `preRelease` remains `true`. - -
- Examples of non-production ready distributions - -- **Pending release (no `releaseDate`):** - ```json - { - "uuid": "e2a1c7b4-3f2d-4e8a-9c1a-7b2e4d5f6a8b", - "version": "11.0.0", - "createdDate": "2025-09-01T00:00:00Z", - "preRelease": true, - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.0?repository_url=https:%2F%2Frepository.apache.org%2Fcontent%2Fgroups%2Fstaging%2F" - } - ] - } - ``` -- **Transition to production-ready (`preRelease` flag turned off, `releaseDate` added)**: - ```json - { - "uuid": "e2a1c7b4-3f2d-4e8a-9c1a-7b2e4d5f6a8b", - "version": "11.0.0", - "createdDate": "2025-09-01T00:00:00Z", - "releaseDate": "2025-09-10T12:00:00Z", - "preRelease": false, - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.0" - } - ] - } - ``` -- **Beta version (has `releaseDate`, but not production ready)**: - ```json - { - "uuid": "95f481df-f760-47f4-b2f2-f8b76d858450", - "version": "11.0.0-M26", - "createdDate": "2024-09-13T17:49:00Z", - "releaseDate": "2024-09-16T17:49:00Z", - "preRelease": true, - "identifiers": [ - { - "idType": "PURL", - "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.0-M26" - } - ] - } - ``` -
+# TEA Collections ## TEA Collection object (TCO) diff --git a/tea-component/tea-release.md b/tea-component/tea-release.md index 1d771ab..2d04bfb 100644 --- a/tea-component/tea-release.md +++ b/tea-component/tea-release.md @@ -4,6 +4,23 @@ A __TEA Component Release__ represents a specific version of a TEA Component lineage. It is the concrete, versioned entity which has collections of security-related artifacts (SBOM, VDR/VEX, attestations, etc.). +A TEA Component Release object represents a specific version of a component, +identified by a unique version number and associated metadata. +Each release may include multiple distributions, +which capture variations such as architecture, packaging, or localization. + +- For software components, + each distribution typically corresponds to a different digital file delivered to users + (e.g., by platform or packaging type). +- For hardware components, distributions may reflect differences in packaging, language, or other physical attributes. + +Each distribution is assigned a unique `distributionType`, defined by the producer, +which is used to associate relevant TEA Artifacts with that distribution. +Since TEA Artifacts can be associated with multiple release objects, +the taxonomy for `distributionType` values should be defined on a TEA service level +and consistently applied to all TEA Artifacts published by that producer. +This ensures global uniqueness and reliable association across releases. + Key attributes: - __uuid__: Unique identifier of the TEA Component Release (uuid) @@ -35,6 +52,8 @@ Key attributes: - __url__: Direct download URL for the distribution - __signatureUrl__: Direct download URL for the distribution's detached signature - __checksums__: Array of checksums for the distribution + - __algType__: Checksum algorithm used. + - __algValue__: Checksum value. Required fields: @@ -88,17 +107,233 @@ The following examples are reused from the OpenAPI schema (`components/schemas/r ] } ``` + +### Examples + +#### Single distribution + +This example shows a TEA Component Release for Apache Log4j Core, which is distributed as a single JAR file. +Even though there is only one distribution, +the `distributions` attribute is included to enable searching for the release by the SHA-256 checksum of the JAR. +This structure also allows for future extensibility if additional distributions are introduced. + +
+ Example of simple release + +```json +{ + "uuid": "b1e2c3d4-5678-49ab-9cde-123456789abc", + "version": "2.24.3", + "createdDate": "2024-12-10T10:51:00Z", + "releaseDate": "2024-12-13T12:52:29Z", + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3" + } + ], + "distributions": [ + { + "distributionType": "jar", + "description": "Binary distribution", + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar" + } + ], + "checksums": [ + { + "algType": "SHA-256", + "algValue": "b1e2c3d4f5a67890b1e2c3d4f5a67890b1e2c3d4f5a67890b1e2c3d4f5a67890" + } + ], + "url": "https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3.jar", + "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3.jar.asc" + } + ] +} +``` +
+ +#### Multiple distributions + +This is an example of a TEA Component Release for Apache Tomcat 11.0.7 binary distributions. +The example defines four distinct `distributionType`s, +which is essential not only for associating the correct SBOMs with each distribution, +but also for accurately tracking and reporting vulnerabilities that may affect only specific distributions. +For instance: + +- The `zip` and `tar.gz` distributions contain only Java JARs. +- The `windows-x64.zip` distribution additionally includes the + [Apache Procrun](https://commons.apache.org/proper/commons-daemon/procrun.html) binary, + which is specific to Windows and may introduce unique vulnerabilities. +- The `windows-x64.exe` distribution contains the same data as `windows-x64.zip`, + but is packaged as a self-extracting installer + created by the [Nullsoft Scriptable Install System](https://nsis.sourceforge.io/Main_Page). + +By defining separate `distributionType`s, +it becomes possible to precisely associate artefacts and vulnerability disclosures with the affected distributions, +ensuring accurate risk assessment and remediation. + +
+ Example of four different binary distributions in the same release + +```json +{ + "uuid": "605d0ecb-1057-40e4-9abf-c400b10f0345", + "version": "11.0.7", + "createdDate": "2025-05-07T18:08:00Z", + "releaseDate": "2025-05-12T18:08:00Z", + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7" + } + ], + "distributions": [ + { + "distributionType": "zip", + "description": "Core binary distribution, zip archive", + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7?type=zip" + } + ], + "checksums": [ + { + "algType": "SHA_256", + "algValue": "9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1" + } + ], + "url": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip", + "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip.asc" + }, + { + "distributionType": "tar.gz", + "description": "Core binary distribution, tar.gz archive", + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7?type=tar.gz" + } + ], + "checksums": [ + { + "algType": "SHA_256", + "algValue": "2fcece641c62ba1f28e1d7b257493151fc44f161fb391015ee6a95fa71632fb9" + } + ], + "url": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.tar.gz", + "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.tar.gz.asc" + }, + { + "distributionType": "windows-x64.zip", + "description": "Core binary distribution, Windows x64 zip archive", + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.7?classifier=windows-x64&type=zip" + } + ], + "checksums": [ + { + "algType": "SHA_256", + "algValue": "62a5c358d87a8ef21d7ec1b3b63c9bbb577453dda9c00cbb522b16cee6c23fc4" + } + ], + "url": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7-windows-x64.zip", + "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip.asc" + }, + { + "distributionType": "windows-x64.exe", + "description": "Core binary distribution, Windows Service Installer (MSI)", + "checksums": [ + { + "algType": "SHA_512", + "algValue": "1d3824e7643c8aba455ab0bd9e67b14a60f2aaa6aa7775116bce40eb0579e8ced162a4f828051d3b867e96ee2858ec5da0cc654e83a83ba30823cbea0df4ff96" + } + ], + "url": "https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe", + "signatureUrl": "https://downloads.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe.asc" + } + ] +} +``` +
+ + ## Handling the Pre-Release flag -The "Pre-release" flag is used to indicate that this is not a final release. -For a given Component with a UUID, the flag can be set to indicate a "test", "beta", "alpha" -or similar non-deployed release. It can only be set when creating the Component. -The TEA implementation may allow it to be unset (False) once. This is to support -situations where a object is promoted as is after testing to production version. The flag can not -be set after initial creation and publication of the Component. +#### Pre-release flag usage + +The `preRelease` flag is used to indicate that a release is not production ready, +regardless of the version naming scheme. +This helps consumers identify non-production releases without relying on conventions like `-beta`, +`-rc`, or `-M` in the version string. + +There are two main scenarios for using the `preRelease` flag: + +- **Pending release:** The distribution is still undergoing quality assurance or review and is not yet officially released. + These typically lack a `releaseDate` attribute. + Once the release is approved, the `preRelease` flag is set to `false` and the `releaseDate` is added. +- **Permanent pre-release:** The distribution is intentionally marked as a pre-release + (e.g., beta, milestone, or release candidate) and will never be considered production ready, + even after all checks are complete. + These may have a `releaseDate`, but `preRelease` remains `true`. + +
+ Examples of non-production ready distributions -If the final version is different from the pre-release (bugs fixed, code changed, different binary) -a new Component with a new UUID and version needs to be created. +- **Pending release (no `releaseDate`):** + ```json + { + "uuid": "e2a1c7b4-3f2d-4e8a-9c1a-7b2e4d5f6a8b", + "version": "11.0.0", + "createdDate": "2025-09-01T00:00:00Z", + "preRelease": true, + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.0?repository_url=https:%2F%2Frepository.apache.org%2Fcontent%2Fgroups%2Fstaging%2F" + } + ] + } + ``` +- **Transition to production-ready (`preRelease` flag turned off, `releaseDate` added)**: + ```json + { + "uuid": "e2a1c7b4-3f2d-4e8a-9c1a-7b2e4d5f6a8b", + "version": "11.0.0", + "createdDate": "2025-09-01T00:00:00Z", + "releaseDate": "2025-09-10T12:00:00Z", + "preRelease": false, + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.0" + } + ] + } + ``` +- **Beta version (has `releaseDate`, but not production ready)**: + ```json + { + "uuid": "95f481df-f760-47f4-b2f2-f8b76d858450", + "version": "11.0.0-M26", + "createdDate": "2024-09-13T17:49:00Z", + "releaseDate": "2024-09-16T17:49:00Z", + "preRelease": true, + "identifiers": [ + { + "idType": "PURL", + "idValue": "pkg:maven/org.apache.tomcat/tomcat@11.0.0-M26" + } + ] + } + ``` +
Notes: From 0654f66a5d42a6ee51c0ecbed7e5d0e9be6cff2e Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 26 Aug 2026 12:23:09 +0200 Subject: [PATCH 07/10] Aligning openapi and markdown docs for collection and artifacts Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 20 ++++---- tea-collection/tea-collection.md | 85 ++++++++++++++++---------------- 2 files changed, 52 insertions(+), 53 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 3b14898..f40bf71 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1303,7 +1303,7 @@ components: May be disabled after the creation of the release object, but can't be enabled after creation of an object. identifiers: type: array - description: List of identifiers for the component + description: Array of identifiers for the component items: "$ref": "#/components/schemas/identifier" distributions: @@ -1377,14 +1377,14 @@ components: type: object properties: distributionId: - description: A unique identifier for the TEA Distribution object + description: A unique identifier for the TEA Distribution object (uuid) "$ref": "#/components/schemas/uuid" description: type: string - description: Free-text description of the distribution. + description: Free-text description of the distribution identifiers: type: array - description: List of identifiers specific to this distribution. + description: Array of identifiers specific to this distribution items: $ref: "#/components/schemas/identifier" url: @@ -1406,7 +1406,7 @@ components: checksums: type: array description: | - List of checksums for the distribution payload retrieved from `url` + Array of checksums for the distribution payload retrieved from `url` (the distribution bytes, not the signature at `signatureUrl`). items: "$ref": "#/components/schemas/checksum" @@ -1543,7 +1543,7 @@ components: "$ref": "#/components/schemas/collection-update-reason" artifacts: type: array - description: List of TEA Artifact objects (may be empty). + description: Array of TEA Artifact objects (may be empty). items: "$ref": "#/components/schemas/artifact" required: @@ -1637,17 +1637,17 @@ components: default: 1 name: type: string - description: Name of TEA Artifact + description: A human-readable name for the artefact type: description: Type of TEA Artifact "$ref": "#/components/schemas/artifact-type" createdDate: - description: The date when the TEA Artifact revision was created. + description: The date and time the TEA Artifact revision was created. "$ref": "#/components/schemas/date-time" distributionIds: type: array description: | - List of TEA Component Release distributions that this TEA Artifact applies to. + Array of TEA Component Release distributions that this TEA Artifact applies to. If absent or empty, the TEA Artifact applies to all distributions. items: "$ref": "#/components/schemas/uuid" @@ -1766,7 +1766,7 @@ components: checksums: type: array description: | - List of checksums for this artifact format's content bytes (the payload + Array of checksums for this artifact format's content bytes (the payload retrieved from `url` or from the artifact download endpoint for this `mediaType`), not the detached signature. items: diff --git a/tea-collection/tea-collection.md b/tea-collection/tea-collection.md index dcff355..427fb8e 100644 --- a/tea-collection/tea-collection.md +++ b/tea-collection/tea-collection.md @@ -1,13 +1,10 @@ -# TEA Collections +# TEA Collection object -## TEA Collection object (TCO) - -For each product and version there is a Tea Collection object, which is a list -of available artefacts for this specific version. The TEA Index is a list of -TEA collections. +For each product and version there is a Tea Collection object (TCO), which is a list +of available artifacts for this specific version. The TEA collection is normally created by the TEA application server at -publication time of artefacts. The publisher may sign the collection +publication time of artifacts. The publisher may sign the collection object as a JSON file at time of publication. A release is never served without a collection. If no artifacts have been @@ -21,11 +18,11 @@ In both cases version 1 is the first collection a client could have retrieved. A server may also synthesize the collection dynamically (see below). If there are any updates of artefacts within a collection for the same -version of a product, then a new TEA Collection object is created and signed. +version of a product, then a new TEA Collection object is created and optionally signed. This update will have the same UUID, but a new version number. A reason for the update will have to be provided. This shall be used to correct mistakes, spelling errors as well as to provide new information -on dynamic artefact types such as LCE or VEX. If the product +on dynamic artifact types such as LCE or VEX. If the product is modified, that is a new product version and that should generate a new collection object with a new UUID and updated metadata. @@ -34,32 +31,32 @@ or a specific version. ### Dynamic or static Collection objects -The TCO is produced by the TEA software platform. There are two ways +The TCO is managed by the TEA software platform. There are two ways to implement this: -* __Dynamic__: The TCO is built for each API request and created +- __Dynamic__: The TCO is built for each API request and created dynamically. -* __Static__: The TCO is built at publication time as a static +- __Static__: The TCO is built at publication time as a static object by the publisher. This object can be digitally signed at publication time and version controlled. ### Collection object - The TEA Collection object has the following parts: +The TEA Collection object has the following parts: - - Preamble - - __uuid__: UUID of the TEA Collection object. - Note that this is equal to the UUID of the associated TEA Component Release object. +- Preamble +- __uuid__: UUID of the TEA Collection object. + This matches the UUID of the associated TEA Component Release object. When updating a collection, only the `version` is changed. - - __version__: TEA Collection version, incremented each time its content changes. +- __version__: TEA Collection version, incremented each time its content changes. Versions start with 1. - - __createdDate__: TEA Collection version release date. - - __belongsTo__: Scope of the collection; enum values `COMPONENT_RELEASE` or `PRODUCT_RELEASE`. - - __updateReason__: Reason for the update/release of the TEA Collection object. - - __type__: Type of update reason. +- __createdDate__: Timestamp when the TEA Collection version was created. +- __belongsTo__: Indicates whether this collection belongs to a Component Release or a Product Release. Enum values `COMPONENT_RELEASE` or `PRODUCT_RELEASE`. +- __updateReason__: Reason for the update/release of the TEA Collection object. + - __type__: Type of update reason. See [reasons for TEA Collection update](#the-reason-for-tco-update-enum) below. - - __comment__: Free text description. - - __artifacts__: List of TEA Artifact objects (required; may be empty). + - __comment__: Free text description. +- __artifacts__: Array of TEA Artifact objects. See [below](#tea-artifact-object). ## TEA Artifact object @@ -84,43 +81,45 @@ A TEA Artifact object contains the following fields: - __version__: An integer with default value 1. Together with *uuid* uniquely identifies the TEA Artifact. - This field can be used to designate successive, immutable revisions of an artefact content (e.g. an updated VEX file). -- __name__: A human-readable name for the artefact. -- __type__: The type of artefact. See [TEA Artifact types](#tea-artefact-types) for allowed values (e.g., `BOM`, `VULNERABILITIES`, `LICENSE`). -- __createdDate__: The date and time the TEA Artefact revision was created. -- __componentDistributions__ (optional): - An array of `distributionType` identifiers indicating which distributions this TEA Artifact applies to. - If omitted, the TEA Artifact applies to all distributions. + This field can be used to designate successive, immutable revisions of an artifact content (e.g. an updated VEX file). +- __name__: A human-readable name for the artifact. +- __type__: The type of TEA artifact. See [TEA Artifact types](#tea-artifact-types) for allowed values (e.g., `BOM`, `VULNERABILITIES`, `LICENSE`). +- __createdDate__: The date and time the TEA Artifact revision was created. +- __distributionIds__: (optional): Array of TEA Component Release distributions that this TEA Artifact applies to. If absent or empty, the TEA Artifact applies to all distributions. - __formats__: - An array of objects, each representing the same artefact content in a different format. + An array of objects, each representing the same artifact content in a different format. The order of the list is not significant. Each format object includes: - __mediaType__: The media type of the document (e.g., `application/vnd.cyclonedx+xml`). Required. A media type appears at most once across the formats of a TEA Artifact revision, so that a format can be selected unambiguously by media type. - - __description__: A free-text description of the artefact format. - - __url__ (optional): An external download URL for the artefact, outside the TEA API. + - __description__: A free-text description of the artifact format. + - __url__ (optional): An external download URL for the artifact, outside the TEA API. This must point to an immutable resource. If present, clients retrieve the content from it. If absent, the TEA server hosts the content itself and clients retrieve it from the artifact download endpoint (`/artifact/{uuid}/{version}/download`), selecting the format by its media type. - - __signatureUrl__ (optional): An external download URL for a detached digital signature of the artefact, outside the TEA API. + - __signatureUrl__ (optional): An external download URL for a detached digital signature of the artifact, outside the TEA API. If present, clients retrieve the signature from it. If absent, clients retrieve it from the artifact signature download endpoint (`/artifact/{uuid}/{version}/signature/download`), which answers `404` when no signature is published for the format. - __checksums__: - An array of checksum objects for the artefact, each containing: + An array of checksum objects for the artifact, each containing: - __algType__: The checksum algorithm used (e.g., `SHA_256`, `SHA3_512`). - __algValue__: The checksum value as a string. +Required fields: + +- uuid, type, formats + ### Notes -- The `formats` array allows the same artefact to be provided in multiple encodings or serializations (e.g., JSON, XML). -- The `checksums` field provides integrity verification for each artefact format. -- Detached signatures, whether at `signatureUrl` or served by the TEA server, enable consumers to verify the authenticity of the artefact. +- The `formats` array allows the same artifact to be provided in multiple encodings or serializations (e.g., JSON, XML). +- The `checksums` field provides integrity verification for each artifact format. +- Detached signatures, whether at `signatureUrl` or served by the TEA server, enable consumers to verify the authenticity of the artifact. - `url` and `signatureUrl` are always external locations; a TEA server that hosts content or signatures itself omits them and serves the bytes from its download endpoints. A TEA access token is sent only to the TEA server's own API, never to an external URL. -- Artefacts should be published to stable, versioned URLs to ensure immutability and traceability. +- artifacts should be published to stable, versioned URLs to ensure immutability and traceability. The `latest` download endpoints are mutable by design and must not be used as a format's `url` or `signatureUrl`. ## The reason for TCO update enum @@ -128,10 +127,10 @@ A TEA Artifact object contains the following fields: | ENUM | Description | |------------------|----------------------------------------| | INITIAL_RELEASE | Initial release of the collection | -| VEX_UPDATED | Updated the VEX artefact(s) | -| ARTIFACT_UPDATED | Updated the artefact(s) other than VEX | -| ARTIFACT_REMOVED | Removal of artefact | -| ARTIFACT_ADDED | Addition of an artefact | +| VEX_UPDATED | Updated the VEX artifact(s) | +| ARTIFACT_UPDATED | Updated the artifact(s) other than VEX | +| ARTIFACT_REMOVED | Removal of artifact | +| ARTIFACT_ADDED | Addition of an artifact | Updates of VEX (CSAF) files may be handled in a different way by a TEA client, producing different alerts than other changes of a collection. From 083f6b685f8145bdced65caa52cf16347a7ad91e Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:50:40 +0200 Subject: [PATCH 08/10] Clarify "identifier" object that is not only used by components Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index f40bf71..c42fd9e 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1053,7 +1053,7 @@ components: description: URI of a human-readable web page with information about the error. identifier: type: object - description: An identifier of the component with a specified type + description: An identifier of a TEA object with a specified type properties: idType: description: Type of identifier, e.g. `TEI`, `PURL`, `CPE` From 3f2d99c11f64377187dc9c9dd5713a35f2165b6a Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 15:50:29 +0200 Subject: [PATCH 09/10] Fix component => product relase Signed-off-by: Olle E. Johansson --- tea-product/tea-product-release.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/tea-product/tea-product-release.md b/tea-product/tea-product-release.md index b7b69af..e1d4097 100644 --- a/tea-product/tea-product-release.md +++ b/tea-product/tea-product-release.md @@ -53,14 +53,14 @@ The following example is reused from the OpenAPI schema (`components/schemas/pro ## Handling the Pre-Release flag The "Pre-release" flag is used to indicate that this is not a final release. -For a given Component with a UUID, the flag can be set to indicate a "test", "beta", "alpha" -or similar non-deployed release. It can only be set when creating the Component. +For a given product release with a UUID, the flag can be set to indicate a "test", "beta", "alpha" +or similar non-deployed release. It can only be set when creating the product release. The TEA implementation may allow it to be unset (False) once. This is to support situations where a object is promoted as is after testing to production version. The flag can not -be set after initial creation and publication of the Component. +be set after initial creation and publication of the product release. If the final version is different from the pre-release (bugs fixed, code changed, different binary) -a new Component with a new UUID and version needs to be created. +a new product release with a new UUID and version needs to be created. ## Notes From 9395c6d36022b02c164b705a7fcb0fcc8ff11a3b Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:55:41 +0200 Subject: [PATCH 10/10] Update TEI: URL examples Signed-off-by: Olle E. Johansson --- tea-component/tea-release.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/tea-component/tea-release.md b/tea-component/tea-release.md index 2d04bfb..9435b0d 100644 --- a/tea-component/tea-release.md +++ b/tea-component/tea-release.md @@ -14,10 +14,10 @@ which capture variations such as architecture, packaging, or localization. (e.g., by platform or packaging type). - For hardware components, distributions may reflect differences in packaging, language, or other physical attributes. -Each distribution is assigned a unique `distributionType`, defined by the producer, +Each distribution is assigned a unique `distributionOd`, defined by the producer, which is used to associate relevant TEA Artifacts with that distribution. Since TEA Artifacts can be associated with multiple release objects, -the taxonomy for `distributionType` values should be defined on a TEA service level +the taxonomy for `distributionId` values should be defined on a TEA service level and consistently applied to all TEA Artifacts published by that producer. This ensures global uniqueness and reliable association across releases. @@ -134,7 +134,7 @@ This structure also allows for future extensibility if additional distributions ], "distributions": [ { - "distributionType": "jar", + "distributionId": "jar", "description": "Binary distribution", "identifiers": [ { @@ -159,7 +159,7 @@ This structure also allows for future extensibility if additional distributions #### Multiple distributions This is an example of a TEA Component Release for Apache Tomcat 11.0.7 binary distributions. -The example defines four distinct `distributionType`s, +The example defines four distinct `distributionId`s, which is essential not only for associating the correct SBOMs with each distribution, but also for accurately tracking and reporting vulnerabilities that may affect only specific distributions. For instance: @@ -172,7 +172,7 @@ For instance: but is packaged as a self-extracting installer created by the [Nullsoft Scriptable Install System](https://nsis.sourceforge.io/Main_Page). -By defining separate `distributionType`s, +By defining separate `distributionId`s, it becomes possible to precisely associate artefacts and vulnerability disclosures with the affected distributions, ensuring accurate risk assessment and remediation. @@ -193,7 +193,7 @@ ensuring accurate risk assessment and remediation. ], "distributions": [ { - "distributionType": "zip", + "distributionId": "zip", "description": "Core binary distribution, zip archive", "identifiers": [ { @@ -211,7 +211,7 @@ ensuring accurate risk assessment and remediation. "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip.asc" }, { - "distributionType": "tar.gz", + "distributionId": "tar.gz", "description": "Core binary distribution, tar.gz archive", "identifiers": [ { @@ -229,7 +229,7 @@ ensuring accurate risk assessment and remediation. "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.tar.gz.asc" }, { - "distributionType": "windows-x64.zip", + "distributionId": "windows-x64.zip", "description": "Core binary distribution, Windows x64 zip archive", "identifiers": [ { @@ -247,7 +247,7 @@ ensuring accurate risk assessment and remediation. "signatureUrl": "https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.7.zip.asc" }, { - "distributionType": "windows-x64.exe", + "distributionId": "windows-x64.exe", "description": "Core binary distribution, Windows Service Installer (MSI)", "checksums": [ {