Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
cb50adb
Require both idType and idValue in identifier
oej Aug 31, 2026
90396f6
Require that productrelease belongs to an identified product
oej Aug 31, 2026
394944d
Make component "release" require component identifier
oej Aug 31, 2026
daf8426
Add required items to collection
oej Aug 31, 2026
756d98c
Update required items for collection-update-reason
oej Aug 31, 2026
c409e3e
Format: URL does not exist in openapi
oej Aug 31, 2026
64b1036
Remove MD5 support
oej Aug 31, 2026
14458b3
Update to ECMA International, TC54 tg 1
oej Aug 31, 2026
6723755
Adding an official description of the TEA project
oej Aug 31, 2026
c7e5aec
Clarifying UUID spec
oej Aug 31, 2026
6a34681
Change date to createdDate
oej Aug 31, 2026
43aeb3b
Remove old stuff from README
oej Sep 12, 2026
11d6451
Modify examples still using "date:" and not "createdDate"
oej Sep 12, 2026
24af890
Add new required fields to examples
oej Sep 12, 2026
e486279
Modify example using MD5 algo (that was removed)
oej Sep 12, 2026
a9535db
Add product UUID in example
oej Sep 15, 2026
990cd06
Remove optional product from product release
oej Sep 15, 2026
d0aa4ce
Add a requirement of minimum one format for each artifact
oej Sep 15, 2026
13f8adb
Convert all "SHA_" to "SHA-"
oej Sep 15, 2026
b249323
Remote format: url
oej Sep 15, 2026
9340889
Fix productrelease requirement (not optional any more)
oej Sep 15, 2026
e41d33b
Add version to artifact example
oej Sep 15, 2026
07730aa
Fix bad example SHA-256 and add component to Tomcat prerelease example
oej Sep 15, 2026
64844d4
Remove "optional" when describing product
oej Sep 16, 2026
d678526
Add missing data in collection examples
oej Sep 16, 2026
d156b07
Add missing fields to component-release-with-collection examples
oej Sep 16, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 2 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,12 +23,6 @@ We encourage developers to start with both client and server implementations of
participate in interoperability tests. These will be organised both as hackathons and
informally using the Slack channel.


Priority issues for v1.0:

- E2e poc of authn/z workflow with TEA consumer spec, including consumer spec adjustment to better support authn/z
- Compliance document workflow, see https://github.com/CycloneDX/transparency-exchange-api/issues/205

Check the list of [implementations](doc/tea-implementations.md) that are available.

## Introduction
Expand Down Expand Up @@ -60,8 +54,8 @@ The working group has produced a list of use cases and requirements for the prot
- [TEA use cases](doc/tea-usecases.md)

## Data model
- [TEA Product Release](tea-product/tea-product-release.md): The primary entry point. The [Transparency Exchange Identifier, TEI](/discovery/readme.md) resolves to a specific Product Release. A Product Release may optionally belong to a [TEA Product](tea-product/tea-product.md).
- [TEA Product](tea-product/tea-product.md): An optional higher-level object that groups a set of Product Releases for a product line or family. Products can be discovered and browsed; releases are accessed via `/product/{uuid}/releases`.
- [TEA Product Release](tea-product/tea-product-release.md): The primary entry point. The [Transparency Exchange Identifier, TEI](/discovery/readme.md) resolves to a specific Product Release. A Product Release belongs to a [TEA Product](tea-product/tea-product.md).
- [TEA Product](tea-product/tea-product.md): A higher-level object that groups a set of Product Releases for a product line or family. Products can be discovered and browsed; releases are accessed via `/product/{uuid}/releases`.
- [TEA Component](tea-component/tea-component.md): Represents a component lineage. A Component is a collection of Component Releases (accessible via `/component/{uuid}/releases`).
- [TEA Release](/tea-component/tea-release.md): A Component Release object. Each Component Release may have its own TEA Collection.
- [TEA Collection](tea-collection/tea-collection.md): A versioned list of artefacts for a specific Release (Component Release) or Product Release. Collections are versioned to indicate changes, e.g., an updated VEX or corrected SBOM.
Expand Down
89 changes: 63 additions & 26 deletions spec/openapi.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,21 @@ openapi: 3.1.1
jsonSchemaDialect: https://spec.openapis.org/oas/3.1/dialect/base
info:
title: Transparency Exchange API
summary: The OWASP Transparency Exchange API specification for consumers and publishers
description: TBC
summary: The OWASP Transparency Exchange API specification for consumers
description: |
The Transparency Exchange API (TEA) aims to facilitate the automated exchange
of supply chain artifacts such as Software Bill of Materials (SBOM),
Vulnerability Exploitability eXchange (VEX), and attestations,
allowing users to automatically discover and consume transparency-related
artifacts for a product. The TEA enhances transparency across the software
supply chain by providing a standardized method to share and access critical
security and compliance information. This automation benefits release management
and optimizes procurement processes, ensuring timely updates and improving risk management.
TEA is developed within the OWASP CycloneDX project and standardised in ECMA International
technical Committee 54, task group 1.
contact:
name: TEA Working Group
email: tbc@somewhere.tld
url: https://github.com/CycloneDX/transparency-exchange-api
name: ECMA International, TC54 tg1
url: https://tc54.org/tea/
license:
name: Apache 2.0
url: https://github.com/CycloneDX/transparency-exchange-api/blob/main/LICENSE
Expand Down Expand Up @@ -912,6 +921,9 @@ components:
idValue:
description: Identifier value
type: string
required:
- idType
- idValue
identifier-type:
type: string
description: Enumeration of identifiers types
Expand Down Expand Up @@ -948,7 +960,7 @@ components:
- CYBER_ESSENTIALS_PLUS
uuid:
type: string
description: A UUID
description: A UUID in lower case (RFC 9562)
format: uuid
pattern: "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"

Expand Down Expand Up @@ -1036,9 +1048,11 @@ components:
- version
- createdDate
- components
- product
examples:
- uuid: 123e4567-e89b-12d3-a456-426614174000
version: "2.24.3"
product: c71b316e-ae77-11f1-aafb-1a52914d44b2
createdDate: 2025-04-01T15:43:00Z
releaseDate: 2025-04-01T15:43:00Z
identifiers:
Expand Down Expand Up @@ -1159,10 +1173,12 @@ components:
- uuid
- version
- createdDate
- component
examples:
# Apache Tomcat 11.0.7
- uuid: 605d0ecb-1057-40e4-9abf-c400b10f0345
version: "11.0.7"
component: c71b316e-ae77-11f1-aafb-1a52914d44b2
createdDate: 2025-05-07T18:08:00Z
releaseDate: 2025-05-12T18:08:00Z
identifiers:
Expand All @@ -1175,7 +1191,7 @@ components:
- idType: PURL
idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=zip
checksums:
- algType: SHA_256
- algType: SHA-256
algValue: 9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1
url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc
Expand All @@ -1185,7 +1201,7 @@ components:
- idType: PURL
idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=tar.gz
checksums:
- algType: SHA_256
- algType: SHA-256
algValue: 2fcece641c62ba1f28e1d7b257493151fc44f161fb391015ee6a95fa71632fb9
url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz.asc
Expand All @@ -1195,20 +1211,21 @@ components:
- idType: PURL
idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?classifier=windows-x64&type=zip
checksums:
- algType: SHA_256
- algType: SHA-256
algValue: 62a5c358d87a8ef21d7ec1b3b63c9bbb577453dda9c00cbb522b16cee6c23fc4
url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6-windows-x64.zip
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc
- distributionId: de45ffaf-e4b5-47b5-be28-444a76df098e
description: Core binary distribution, Windows Service Installer (MSI)
checksums:
- algType: SHA_512
- algType: SHA-512
algValue: 1d3824e7643c8aba455ab0bd9e67b14a60f2aaa6aa7775116bce40eb0579e8ced162a4f828051d3b867e96ee2858ec5da0cc654e83a83ba30823cbea0df4ff96
url: https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe
signatureUrl: https://downloads.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe.asc
# A pre-release of Apache Tomcat
- uuid: 95f481df-f760-47f4-b2f2-f8b76d858450
version: "11.0.0-M26"
component: 8738fa52-b0ea-11f1-9e47-1a52914d44b2
createdDate: 2024-09-13T17:49:00Z
preRelease: true
identifiers:
Expand All @@ -1231,11 +1248,11 @@ components:
url:
type: string
description: Direct download URL for the distribution.
format: url
format: uri
signatureUrl:
type: string
description: Direct download URL for the distribution's external signature.
format: url
format: uri
checksums:
type: array
description: List of checksums for the distribution.
Expand All @@ -1250,7 +1267,7 @@ components:
- idType: PURL
idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=zip
checksums:
- algType: SHA_256
- algType: SHA-256
algValue: 9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1
url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc
Expand All @@ -1260,7 +1277,7 @@ components:
- idType: PURL
idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?type=tar.gz
checksums:
- algType: SHA_256
- algType: SHA-256
algValue: 2fcece641c62ba1f28e1d7b257493151fc44f161fb391015ee6a95fa71632fb9
url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.tar.gz.asc
Expand All @@ -1270,14 +1287,14 @@ components:
- idType: PURL
idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.6?classifier=windows-x64&type=zip
checksums:
- algType: SHA_256
- algType: SHA-256
algValue: 62a5c358d87a8ef21d7ec1b3b63c9bbb577453dda9c00cbb522b16cee6c23fc4
url: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6-windows-x64.zip
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat/11.0.7/tomcat-11.0.6.zip.asc
- distributionId: de45ffaf-e4b5-47b5-be28-444a76df098e
description: Core binary distribution, Windows Service Installer (MSI)
checksums:
- algType: SHA_512
- algType: SHA-512
algValue: 1d3824e7643c8aba455ab0bd9e67b14a60f2aaa6aa7775116bce40eb0579e8ced162a4f828051d3b867e96ee2858ec5da0cc654e83a83ba30823cbea0df4ff96
url: https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe
signatureUrl: https://downloads.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.exe.asc
Expand All @@ -1301,20 +1318,23 @@ components:
version: "11.0.7"
createdDate: 2025-05-07T18:08:00Z
releaseDate: 2025-05-12T18:08:00Z
component: 7c472640-b1ae-11f1-990c-1a52914d44b2
identifiers:
- idType: PURL
idValue: pkg:maven/org.apache.tomcat/tomcat@11.0.7
latestCollection:
uuid: 605d0ecb-1057-40e4-9abf-c400b10f0345
version: 2
date: 2025-05-12T18:08:00Z
createdDate: 2025-05-12T18:08:00Z
belongsTo: COMPONENT_RELEASE
updateReason:
type: INITIAL_RELEASE
comment: Initial collection for this release
artifacts:
- uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce
name: Build SBOM
version: 2
createdDate: 2025-05-07T18:08:00Z
type: BOM
formats:
- mediaType: application/vnd.cyclonedx+xml
Expand All @@ -1325,6 +1345,8 @@ components:
algValue: 9da736a1cdd27231e70187cbc67398d29ca0b714f885e7032da9f1fb247693c1
- uuid: dfa35519-9734-4259-bba1-3e825cf4be06
name: Vulnerability Disclosure Report
version: 4
createdDate: 2025-05-09T18:08:00Z
type: VULNERABILITIES
formats:
- mediaType: application/vnd.cyclonedx+xml
Expand Down Expand Up @@ -1352,7 +1374,7 @@ components:
description: |
TEA Collection version, incremented each time its content changes.
Versions start with 1.
date:
createdDate:
Comment thread
oej marked this conversation as resolved.
description: The date when the TEA Collection version was created.
"$ref": "#/components/schemas/date-time"
belongsTo:
Expand All @@ -1366,16 +1388,25 @@ components:
description: List of TEA Artifact objects.
items:
"$ref": "#/components/schemas/artifact"
required:
- uuid
- version
- createdDate
- belongsTo
- updateReason
examples:
# Documents in the latest release of Log4j Core
- uuid: 4c72fe22-9d83-4c2f-8eba-d6db484f32c8
version: 10
date: 2024-12-13T00:00:00Z
createdDate: 2024-12-13T00:00:00Z
belongsTo: COMPONENT_RELEASE
updateReason:
type: ARTIFACT_UPDATED
comment: VDR file updated
artifacts:
- uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce
createdDate: 2024-12-13T00:00:00Z
version: 2
name: Build SBOM
type: BOM
formats:
Expand All @@ -1384,11 +1415,10 @@ components:
url: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml.asc
checksums:
- algType: MD5
Comment thread
oej marked this conversation as resolved.
algValue: 2e1a525afc81b0a8ecff114b8b743de9
- algType: SHA-1
algValue: 5a7d4caef63c5c5ccdf07c39337323529eb5a770
- uuid: dfa35519-9734-4259-bba1-3e825cf4be06
createdDate: 2024-12-15T00:00:00Z
version: 7
name: Vulnerability Disclosure Report
type: VULNERABILITIES
Expand All @@ -1410,6 +1440,8 @@ components:
comment:
type: string
description: Free text description
required:
- type
collection-update-reason-type:
type: string
description: Type of TEA collection update
Expand Down Expand Up @@ -1464,6 +1496,7 @@ components:
The distribution IDs of the TEA component release distributions that this TEA Artifact applies to.
formats:
type: array
minItems: 1
description: |
List of objects with the same content, but in different formats.
The order of the list has no significance.
Expand All @@ -1473,24 +1506,29 @@ components:
- uuid
- type
- formats
- createdDate
- version
examples:
- uuid: 1cb47b95-8bf8-3bad-a5a4-0d54d86e10ce
version: 2
name: Build SBOM
type: BOM
createdDate: 2026-05-15T00:00:00Z
formats:
- mediaType: application/vnd.cyclonedx+xml
description: CycloneDX SBOM (XML)
url: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml
signatureUrl: https://repo.maven.apache.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-cyclonedx.xml.asc
checksums:
- algType: MD5
algValue: 2e1a525afc81b0a8ecff114b8b743de9
- algType: SHA-256
algValue: e04c9d55986d7194822eaa4f8115a77f801844d807ad6e0d454ac31dd41861e5
- algType: SHA-1
algValue: 5a7d4caef63c5c5ccdf07c39337323529eb5a770
- uuid: dfa35519-9734-4259-bba1-3e825cf4be06
version: 7
name: Vulnerability Disclosure Report
type: VULNERABILITIES
createdDate: 2026-05-15T00:00:00Z
formats:
- mediaType: application/vnd.cyclonedx+xml
description: CycloneDX VDR (XML)
Expand Down Expand Up @@ -1546,7 +1584,7 @@ components:
pre-signed, or covered by credentials the client arranges separately. When
the URL is pre-signed it may expire; clients should not retain it beyond the
freshness lifetime of the response that carried it.
format: url
format: uri
signatureUrl:
type: string
description: |
Expand All @@ -1563,7 +1601,7 @@ components:

This specification does not define which signature technology is used, nor
model the signing algorithm, key, or certificate chain.
format: url
format: uri
checksums:
type: array
description: List of checksums for the TEA Artifact
Expand All @@ -1585,7 +1623,6 @@ components:
type: string
description: Checksum algorithm
enum:
- MD5
- SHA-1
- SHA-256
- SHA-384
Expand Down
2 changes: 1 addition & 1 deletion tea-product/tea-product-release.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@ The following example is reused from the OpenAPI schema (`components/schemas/pro
"version": "2.24.3",
"createdDate": "2025-04-01T15:43:00Z",
"releaseDate": "2025-04-01T15:43:00Z",
"product": "9c622dd2-b0df-11f1-9796-1a52914d44b2",
"identifiers": [
{
"idType": "TEI",
Expand All @@ -47,5 +48,4 @@ The following example is reused from the OpenAPI schema (`components/schemas/pro
```

Notes:
- Property `product` exists in the schema and links a product release to its parent product; it may not be present in all examples.
- Use uppercase idType values exactly as defined by the schema enum: CPE, TEI, PURL.
3 changes: 1 addition & 2 deletions tea-product/tea-product.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# The TEA product API

After TEA discovery, the [Transparency Exchange Identifier (TEI)](/discovery/readme.md) resolves to a specific TEA Product Release, which represents a concrete, versioned offering. A TEA Product is an optional higher-level object that groups multiple Product Releases for a product line or family and can be browsed via `/product/{uuid}/releases`.
After TEA discovery, the [Transparency Exchange Identifier (TEI)](/discovery/readme.md) resolves to a specific TEA Product Release, which represents a concrete, versioned offering. A TEA Product is a higher-level object that groups multiple Product Releases for a product line or family and can be browsed via `/product/{uuid}/releases`.

- A product release may consist of a single component, the output will be metadata about the
product and the TEA COMPONENT object.
Expand All @@ -20,7 +20,6 @@ which products and versions are supported for a specific user.

A TEA Product Release will be the starting
point of discovery. The TEA product release will list all included components

with the UUID of the TEA component. The reference list may also include
a UUID of a specific release of a component in the case where a product
always includes a single release of the component.
Expand Down