From cb50adb689c7c2f5c3a61d99d280ca2937567549 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 16:03:05 +0200 Subject: [PATCH 01/26] Require both idType and idValue in identifier Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 529a7b5..9111a42 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -912,6 +912,9 @@ components: idValue: description: Identifier value type: string + required: + - idType + - idValue identifier-type: type: string description: Enumeration of identifiers types From 90396f6a2240c5917a068344a03e8837d7e0558d Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 16:06:36 +0200 Subject: [PATCH 02/26] Require that productrelease belongs to an identified product Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 9111a42..7305355 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1039,6 +1039,7 @@ components: - version - createdDate - components + - product examples: - uuid: 123e4567-e89b-12d3-a456-426614174000 version: "2.24.3" From 394944d01a9b4f1ce98ae097fd2ab7fd7f09a538 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 16:09:35 +0200 Subject: [PATCH 03/26] Make component "release" require component identifier Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 7305355..f54625c 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1163,6 +1163,7 @@ components: - uuid - version - createdDate + - component examples: # Apache Tomcat 11.0.7 - uuid: 605d0ecb-1057-40e4-9abf-c400b10f0345 From daf84267d29aec038a24a75bf76fee7e5c63c97c Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 16:12:48 +0200 Subject: [PATCH 04/26] Add required items to collection Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index f54625c..b2f9896 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1371,6 +1371,12 @@ components: description: List of TEA Artifact objects. items: "$ref": "#/components/schemas/artifact" + required: + - uuid + - version + - date + - belongsTo + - updateReason examples: # Documents in the latest release of Log4j Core - uuid: 4c72fe22-9d83-4c2f-8eba-d6db484f32c8 @@ -1478,6 +1484,8 @@ components: - uuid - type - formats + - createdDate + - version examples: - uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce name: Build SBOM From 756d98c1a7bb26f5c3a105bce46b452fba366184 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 16:24:11 +0200 Subject: [PATCH 05/26] Update required items for collection-update-reason Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index b2f9896..d025c94 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1421,6 +1421,8 @@ components: comment: type: string description: Free text description + required: + - type collection-update-reason-type: type: string description: Type of TEA collection update From c409e3ef91d60ba8e238d74e212242fcf249806e Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:20:08 +0200 Subject: [PATCH 06/26] Format: URL does not exist in openapi Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index d025c94..5402a85 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1236,11 +1236,11 @@ components: url: type: string description: Direct download URL for the distribution. - format: url + format: uri signatureUrl: type: string description: Direct download URL for the distribution's external signature. - format: url + format: uri checksums: type: array description: List of checksums for the distribution. From 64b1036c1ae8dd34004aa6d867c2888e3d277042 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:25:59 +0200 Subject: [PATCH 07/26] Remove MD5 support Check RFC 6151 Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 3 --- 1 file changed, 3 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 5402a85..7885ac8 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1395,8 +1395,6 @@ components: url: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml signatureUrl: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml.asc checksums: - - algType: MD5 - algValue: 2e1a525afc81b0a8ecff114b8b743de9 - algType: SHA-1 algValue: 5a7d4caef63c5c5ccdf07c39337323529eb5a770 - uuid: dfa35519-9734-4259-bba1-3e825cf4be06 @@ -1600,7 +1598,6 @@ components: type: string description: Checksum algorithm enum: - - MD5 - SHA-1 - SHA-256 - SHA-384 From 14458b373423fe767f0691bbd757cb67befc6861 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:29:08 +0200 Subject: [PATCH 08/26] Update to ECMA International, TC54 tg 1 Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 7885ac8..6ef679e 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -6,9 +6,8 @@ info: summary: The OWASP Transparency Exchange API specification for consumers and publishers description: TBC contact: - name: TEA Working Group - email: tbc@somewhere.tld - url: https://github.com/CycloneDX/transparency-exchange-api + name: ECMA International, TC54 tg1 + url: https://tc54.org/tea/ license: name: Apache 2.0 url: https://github.com/CycloneDX/transparency-exchange-api/blob/main/LICENSE From 6723755f234941b31a81d9fa9cbcb3703c978d8c Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:32:26 +0200 Subject: [PATCH 09/26] Adding an official description of the TEA project Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 6ef679e..7a40887 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -3,8 +3,18 @@ openapi: 3.1.1 jsonSchemaDialect: https://spec.openapis.org/oas/3.1/dialect/base info: title: Transparency Exchange API - summary: The OWASP Transparency Exchange API specification for consumers and publishers - description: TBC + summary: The OWASP Transparency Exchange API specification for consumers + description: | + The Transparency Exchange API (TEA) aims to facilitate the automated exchange + of supply chain artifacts such as Software Bill of Materials (SBOM), + Vulnerability Exploitability eXchange (VEX), and attestations, + allowing users to automatically discover and consume transparency-related + artifacts for a product. The TEA enhances transparency across the software + supply chain by providing a standardized method to share and access critical + security and compliance information. This automation benefits release management + and optimizes procurement processes, ensuring timely updates and improving risk management. + TEA is developed within the OWASP CycloneDX project and standardised in ECMA International + technical Committee 54, task group 1. contact: name: ECMA International, TC54 tg1 url: https://tc54.org/tea/ From c7e5aecfd0e75620a53fbdd809471ca533129c65 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:49:27 +0200 Subject: [PATCH 10/26] Clarifying UUID spec Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 7a40887..37b4bf7 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -960,7 +960,7 @@ components: - CYBER_ESSENTIALS_PLUS uuid: type: string - description: A UUID + description: A UUID in lower case (RFC 9562) format: uuid pattern: "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" From 6a34681d9543e9dc85d21548ac63a65e53d69ba0 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Mon, 31 Aug 2026 17:58:26 +0200 Subject: [PATCH 11/26] Change date to createdDate this means that this PR will have to go in after #260 Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 37b4bf7..1b3a73d 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1366,7 +1366,7 @@ components: description: | TEA Collection version, incremented each time its content changes. Versions start with 1. - date: + createdDate: description: The date when the TEA Collection version was created. "$ref": "#/components/schemas/date-time" belongsTo: @@ -1383,7 +1383,7 @@ components: required: - uuid - version - - date + - createdDate - belongsTo - updateReason examples: From 43aeb3b6a0df665e074c20d85cf476018fa06024 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Sat, 12 Sep 2026 08:55:34 +0200 Subject: [PATCH 12/26] Remove old stuff from README Signed-off-by: Olle E. Johansson --- README.md | 6 ------ 1 file changed, 6 deletions(-) diff --git a/README.md b/README.md index 13e9568..20a6897 100644 --- a/README.md +++ b/README.md @@ -23,12 +23,6 @@ We encourage developers to start with both client and server implementations of participate in interoperability tests. These will be organised both as hackathons and informally using the Slack channel. - -Priority issues for v1.0: - -- E2e poc of authn/z workflow with TEA consumer spec, including consumer spec adjustment to better support authn/z -- Compliance document workflow, see https://github.com/CycloneDX/transparency-exchange-api/issues/205 - Check the list of [implementations](doc/tea-implementations.md) that are available. ## Introduction From 11d645174246ab1db1826465e525032ce381679d Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Sat, 12 Sep 2026 08:59:12 +0200 Subject: [PATCH 13/26] Modify examples still using "date:" and not "createdDate" Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 1b3a73d..c33da98 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1321,7 +1321,7 @@ components: latestCollection: uuid: 605d0ecb-1057-40e4-9abf-c400b10f0345 version: 2 - date: 2025-05-12T18:08:00Z + createdDate: 2025-05-12T18:08:00Z belongsTo: COMPONENT_RELEASE updateReason: type: INITIAL_RELEASE @@ -1390,7 +1390,7 @@ components: # Documents in the latest release of Log4j Core - uuid: 4c72fe22-9d83-4c2f-8eba-d6db484f32c8 version: 10 - date: 2024-12-13T00:00:00Z + createdDate: 2024-12-13T00:00:00Z updateReason: type: ARTIFACT_UPDATED comment: VDR file updated From 24af89019833b92c74a5297ff5a398ab3dfac97f Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Sat, 12 Sep 2026 09:05:05 +0200 Subject: [PATCH 14/26] Add new required fields to examples Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index c33da98..1625d70 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1052,6 +1052,7 @@ components: examples: - uuid: 123e4567-e89b-12d3-a456-426614174000 version: "2.24.3" + product: c71b316e-ae77-11f1-aafb-1a52914d44b2 createdDate: 2025-04-01T15:43:00Z releaseDate: 2025-04-01T15:43:00Z identifiers: @@ -1177,6 +1178,7 @@ components: # Apache Tomcat 11.0.7 - uuid: 605d0ecb-1057-40e4-9abf-c400b10f0345 version: "11.0.7" + component: c71b316e-ae77-11f1-aafb-1a52914d44b2 createdDate: 2025-05-07T18:08:00Z releaseDate: 2025-05-12T18:08:00Z identifiers: @@ -1391,6 +1393,7 @@ components: - uuid: 4c72fe22-9d83-4c2f-8eba-d6db484f32c8 version: 10 createdDate: 2024-12-13T00:00:00Z + belongsTo: COMPONENT_RELEASE updateReason: type: ARTIFACT_UPDATED comment: VDR file updated @@ -1499,6 +1502,7 @@ components: - uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce name: Build SBOM type: BOM + createdDate: 2026-05-15T00:00:00Z formats: - mediaType: application/vnd.cyclonedx+xml description: CycloneDX SBOM (XML) @@ -1513,6 +1517,7 @@ components: version: 7 name: Vulnerability Disclosure Report type: VULNERABILITIES + createdDate: 2026-05-15T00:00:00Z formats: - mediaType: application/vnd.cyclonedx+xml description: CycloneDX VDR (XML) From e486279f441ee9e5ceef002a2cd9163632e2842b Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Sat, 12 Sep 2026 10:56:11 +0200 Subject: [PATCH 15/26] Modify example using MD5 algo (that was removed) Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 1625d70..f79888b 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1509,7 +1509,7 @@ components: url: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml signatureUrl: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml.asc checksums: - - algType: MD5 + - algType: SHA_256 algValue: 2e1a525afc81b0a8ecff114b8b743de9 - algType: SHA-1 algValue: 5a7d4caef63c5c5ccdf07c39337323529eb5a770 From a9535db832e2aa890c4180539d6f6a773cbe0efb Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 10:30:09 +0200 Subject: [PATCH 16/26] Add product UUID in example Signed-off-by: Olle E. Johansson --- tea-product/tea-product-release.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tea-product/tea-product-release.md b/tea-product/tea-product-release.md index ebe419d..6097e50 100644 --- a/tea-product/tea-product-release.md +++ b/tea-product/tea-product-release.md @@ -28,6 +28,7 @@ The following example is reused from the OpenAPI schema (`components/schemas/pro "version": "2.24.3", "createdDate": "2025-04-01T15:43:00Z", "releaseDate": "2025-04-01T15:43:00Z", + "product": "9c622dd2-b0df-11f1-9796-1a52914d44b2", "identifiers": [ { "idType": "TEI", @@ -47,5 +48,4 @@ The following example is reused from the OpenAPI schema (`components/schemas/pro ``` Notes: -- Property `product` exists in the schema and links a product release to its parent product; it may not be present in all examples. - Use uppercase idType values exactly as defined by the schema enum: CPE, TEI, PURL. From 990cd06b7e952de6cdd3f7d0ea1837a84f895c42 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 10:31:34 +0200 Subject: [PATCH 17/26] Remove optional product from product release Signed-off-by: Olle E. Johansson --- tea-product/tea-product.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/tea-product/tea-product.md b/tea-product/tea-product.md index 8bd7290..a401309 100644 --- a/tea-product/tea-product.md +++ b/tea-product/tea-product.md @@ -1,6 +1,6 @@ # The TEA product API -After TEA discovery, the [Transparency Exchange Identifier (TEI)](/discovery/readme.md) resolves to a specific TEA Product Release, which represents a concrete, versioned offering. A TEA Product is an optional higher-level object that groups multiple Product Releases for a product line or family and can be browsed via `/product/{uuid}/releases`. +After TEA discovery, the [Transparency Exchange Identifier (TEI)](/discovery/readme.md) resolves to a specific TEA Product Release, which represents a concrete, versioned offering. A TEA Product is a higher-level object that groups multiple Product Releases for a product line or family and can be browsed via `/product/{uuid}/releases`. - A product release may consist of a single component, the output will be metadata about the product and the TEA COMPONENT object. @@ -20,7 +20,6 @@ which products and versions are supported for a specific user. A TEA Product Release will be the starting point of discovery. The TEA product release will list all included components - with the UUID of the TEA component. The reference list may also include a UUID of a specific release of a component in the case where a product always includes a single release of the component. From d0aa4ce06ccae70cb5aef64ae637b2bdc0a2f8fd Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 10:33:11 +0200 Subject: [PATCH 18/26] Add a requirement of minimum one format for each artifact Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index f79888b..f60bc89 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1487,6 +1487,7 @@ components: The distribution IDs of the TEA component release distributions that this TEA Artifact applies to. formats: type: array + minItems: 1 description: | List of objects with the same content, but in different formats. The order of the list has no significance. From 13f8adb3f5f798178ede0fa8a6c864f8fbf663f3 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 10:35:21 +0200 Subject: [PATCH 19/26] Convert all "SHA_" to "SHA-" Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index f60bc89..a8c050e 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1191,7 +1191,7 @@ components: - idType: PURL idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=zip checksums: - - algType: SHA_256 + - algType: SHA-256 algValue: 9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1 url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc @@ -1201,7 +1201,7 @@ components: - idType: PURL idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=tar.gz checksums: - - algType: SHA_256 + - algType: SHA-256 algValue: 2fcece641c62ba1f28e1d7b257493151fc44f161fb391015ee6a95fa71632fb9 url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz.asc @@ -1211,14 +1211,14 @@ components: - idType: PURL idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?classifier=windows-x64&type=zip checksums: - - algType: SHA_256 + - algType: SHA-256 algValue: 62a5c358d87a8ef21d7ec1b3b63c9bbb577453dda9c00cbb522b16cee6c23fc4 url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6-windows-x64.zip signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc - distributionId: de45ffaf-e4b5-47b5-be28-444a76df098e description: Core binary distribution, Windows Service Installer (MSI) checksums: - - algType: SHA_512 + - algType: SHA-512 algValue: 1d3824e7643c8aba455ab0bd9e67b14a60f2aaa6aa7775116bce40eb0579e8ced162a4f828051d3b867e96ee2858ec5da0cc654e83a83ba30823cbea0df4ff96 url: https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe signatureUrl: https://downloads.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe.asc @@ -1266,7 +1266,7 @@ components: - idType: PURL idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=zip checksums: - - algType: SHA_256 + - algType: SHA-256 algValue: 9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1 url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc @@ -1276,7 +1276,7 @@ components: - idType: PURL idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=tar.gz checksums: - - algType: SHA_256 + - algType: SHA-256 algValue: 2fcece641c62ba1f28e1d7b257493151fc44f161fb391015ee6a95fa71632fb9 url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz.asc @@ -1286,14 +1286,14 @@ components: - idType: PURL idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?classifier=windows-x64&type=zip checksums: - - algType: SHA_256 + - algType: SHA-256 algValue: 62a5c358d87a8ef21d7ec1b3b63c9bbb577453dda9c00cbb522b16cee6c23fc4 url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6-windows-x64.zip signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc - distributionId: de45ffaf-e4b5-47b5-be28-444a76df098e description: Core binary distribution, Windows Service Installer (MSI) checksums: - - algType: SHA_512 + - algType: SHA-512 algValue: 1d3824e7643c8aba455ab0bd9e67b14a60f2aaa6aa7775116bce40eb0579e8ced162a4f828051d3b867e96ee2858ec5da0cc654e83a83ba30823cbea0df4ff96 url: https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe signatureUrl: https://downloads.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe.asc @@ -1510,7 +1510,7 @@ components: url: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml signatureUrl: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml.asc checksums: - - algType: SHA_256 + - algType: SHA-256 algValue: 2e1a525afc81b0a8ecff114b8b743de9 - algType: SHA-1 algValue: 5a7d4caef63c5c5ccdf07c39337323529eb5a770 From b24932347107b06a398c00374c6ff063e7f67580 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 10:41:56 +0200 Subject: [PATCH 20/26] Remote format: url Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index a8c050e..964fc9a 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1574,7 +1574,7 @@ components: pre-signed, or covered by credentials the client arranges separately. When the URL is pre-signed it may expire; clients should not retain it beyond the freshness lifetime of the response that carried it. - format: url + format: uri signatureUrl: type: string description: | @@ -1591,7 +1591,7 @@ components: This specification does not define which signature technology is used, nor model the signing algorithm, key, or certificate chain. - format: url + format: uri checksums: type: array description: List of checksums for the TEA Artifact From 934088991150cd8d9a086e300051de552e73b7e2 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 11:44:39 +0200 Subject: [PATCH 21/26] Fix productrelease requirement (not optional any more) Signed-off-by: Olle E. Johansson --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 20a6897..47f8331 100644 --- a/README.md +++ b/README.md @@ -54,7 +54,7 @@ The working group has produced a list of use cases and requirements for the prot - [TEA use cases](doc/tea-usecases.md) ## Data model -- [TEA Product Release](tea-product/tea-product-release.md): The primary entry point. The [Transparency Exchange Identifier, TEI](/discovery/readme.md) resolves to a specific Product Release. A Product Release may optionally belong to a [TEA Product](tea-product/tea-product.md). +- [TEA Product Release](tea-product/tea-product-release.md): The primary entry point. The [Transparency Exchange Identifier, TEI](/discovery/readme.md) resolves to a specific Product Release. A Product Release belongs to a [TEA Product](tea-product/tea-product.md). - [TEA Product](tea-product/tea-product.md): An optional higher-level object that groups a set of Product Releases for a product line or family. Products can be discovered and browsed; releases are accessed via `/product/{uuid}/releases`. - [TEA Component](tea-component/tea-component.md): Represents a component lineage. A Component is a collection of Component Releases (accessible via `/component/{uuid}/releases`). - [TEA Release](/tea-component/tea-release.md): A Component Release object. Each Component Release may have its own TEA Collection. From e41d33bbdebf85478d3c27a9852d92f57c366c63 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 11:46:25 +0200 Subject: [PATCH 22/26] Add version to artifact example Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 964fc9a..07134ee 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1501,6 +1501,7 @@ components: - version examples: - uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce + version: 2 name: Build SBOM type: BOM createdDate: 2026-05-15T00:00:00Z From 07730aaadbeb4a975ead80ac86abeb6470939370 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Tue, 15 Sep 2026 11:49:41 +0200 Subject: [PATCH 23/26] Fix bad example SHA-256 and add component to Tomcat prerelease example Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 07134ee..43205e6 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1225,6 +1225,7 @@ components: # A pre-release of Apache Tomcat - uuid: 95f481df-f760-47f4-b2f2-f8b76d858450 version: "11.0.0-M26" + component: 8738fa52-b0ea-11f1-9e47-1a52914d44b2 createdDate: 2024-09-13T17:49:00Z preRelease: true identifiers: @@ -1512,7 +1513,7 @@ components: signatureUrl: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml.asc checksums: - algType: SHA-256 - algValue: 2e1a525afc81b0a8ecff114b8b743de9 + algValue: e04c9d55986d7194822eaa4f8115a77f801844d807ad6e0d454ac31dd41861e5 - algType: SHA-1 algValue: 5a7d4caef63c5c5ccdf07c39337323529eb5a770 - uuid: dfa35519-9734-4259-bba1-3e825cf4be06 From 64844d4c5891838ad8a8b6fd0d8095ca2193402f Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 16 Sep 2026 11:00:59 +0200 Subject: [PATCH 24/26] Remove "optional" when describing product Signed-off-by: Olle E. Johansson --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 47f8331..29cd0c5 100644 --- a/README.md +++ b/README.md @@ -55,7 +55,7 @@ The working group has produced a list of use cases and requirements for the prot ## Data model - [TEA Product Release](tea-product/tea-product-release.md): The primary entry point. The [Transparency Exchange Identifier, TEI](/discovery/readme.md) resolves to a specific Product Release. A Product Release belongs to a [TEA Product](tea-product/tea-product.md). -- [TEA Product](tea-product/tea-product.md): An optional higher-level object that groups a set of Product Releases for a product line or family. Products can be discovered and browsed; releases are accessed via `/product/{uuid}/releases`. +- [TEA Product](tea-product/tea-product.md): A higher-level object that groups a set of Product Releases for a product line or family. Products can be discovered and browsed; releases are accessed via `/product/{uuid}/releases`. - [TEA Component](tea-component/tea-component.md): Represents a component lineage. A Component is a collection of Component Releases (accessible via `/component/{uuid}/releases`). - [TEA Release](/tea-component/tea-release.md): A Component Release object. Each Component Release may have its own TEA Collection. - [TEA Collection](tea-collection/tea-collection.md): A versioned list of artefacts for a specific Release (Component Release) or Product Release. Collections are versioned to indicate changes, e.g., an updated VEX or corrected SBOM. From d6785263fdf54b31194cfbaa4500bb4e62818e9d Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 16 Sep 2026 11:04:24 +0200 Subject: [PATCH 25/26] Add missing data in collection examples Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 43205e6..9c6abbd 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1400,6 +1400,8 @@ components: comment: VDR file updated artifacts: - uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce + createdDate: 2024-12-13T00:00:00Z + version: 2 name: Build SBOM type: BOM formats: @@ -1411,6 +1413,7 @@ components: - algType: SHA-1 algValue: 5a7d4caef63c5c5ccdf07c39337323529eb5a770 - uuid: dfa35519-9734-4259-bba1-3e825cf4be06 + createdDate: 2024-12-15T00:00:00Z version: 7 name: Vulnerability Disclosure Report type: VULNERABILITIES From d156b07a2c31c403e2c1e31615a7d58e2fbfcba0 Mon Sep 17 00:00:00 2001 From: "Olle E. Johansson" Date: Wed, 16 Sep 2026 11:10:58 +0200 Subject: [PATCH 26/26] Add missing fields to component-release-with-collection examples Signed-off-by: Olle E. Johansson --- spec/openapi.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/spec/openapi.yaml b/spec/openapi.yaml index 9c6abbd..862578a 100644 --- a/spec/openapi.yaml +++ b/spec/openapi.yaml @@ -1318,6 +1318,7 @@ components: version: "11.0.7" createdDate: 2025-05-07T18:08:00Z releaseDate: 2025-05-12T18:08:00Z + component: 7c472640-b1ae-11f1-990c-1a52914d44b2 identifiers: - idType: PURL idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.7 @@ -1332,6 +1333,8 @@ components: artifacts: - uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce name: Build SBOM + version: 2 + createdDate: 2025-05-07T18:08:00Z type: BOM formats: - mediaType: application/vnd.cyclonedx+xml @@ -1342,6 +1345,8 @@ components: algValue: 9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1 - uuid: dfa35519-9734-4259-bba1-3e825cf4be06 name: Vulnerability Disclosure Report + version: 4 + createdDate: 2025-05-09T18:08:00Z type: VULNERABILITIES formats: - mediaType: application/vnd.cyclonedx+xml