Comments (9)
please can you provide a clearer description?
from corim.
Architecturally CoMID and CoSWID/SWID are independent units with different purposes.
They may re-use or share types among them. If that is the case one should extract common types which is shared across
these two and move them to common package. This removes the need for using SWID Package inside CoMID package and vice versa!
from corim.
Since the dependency is not circular, I don't see the problem with the current arrangement (i.e., CoMID reusing SWID defined types). Note that this is also true at a higher level than the code organisation: CoMID CDDL actually reuses some CoSWID CDDL types.
from corim.
Another problem I see is that if someone modifies the base type used inside CoSWID it unknowingly impacts CoMID.
from corim.
The assumption we are building on here is that the type is univocally defined by the CoSWID spec.
from corim.
Was an OK assumption till the scope of type was restricted to CoSWID specification. Also SWID and CoSWID specification also do not share tag id internally so, if we plan to share among various packages, then best to define them in a common place.
from corim.
Was an OK assumption till the scope of type was restricted to CoSWID specification.
Why? It is an OK assumption until the CoSWID spec changes -- which is extremely unlikely at this point in time.
Also SWID and CoSWID specification also do not share tag id internally
I don't think this premise is correct: SWID and CoSWID do in fact share the "tag id" definition (with CoSWID.tag-id being a more stringently typed version of SWID.TagId).
from corim.
I think this is OBE?
from corim.
They share hash-entry with includes alg-id (I'm not sure how the alg-ids are registered such that there is interoperability guarantees)
from corim.
Related Issues (20)
- UUID MKey should handle the (special) nil value
- Restructuring the documentation of CoCli HOT 2
- Create a New Release for `CoRIM` package
- signedcorim_test has outdated schema for serialized payload?
- Introduce `tagged bytes` as one of the types within Environment Identifiers (ClassID, Instance and Group)
- Implement Integrity Register changes
- Use `tag` URIs rather than `http` for profile identifiers
- CoMID generates incorrect triple index for `identity-triples` and `attest-key-triples` HOT 1
- Bug: cocli corim display HOT 1
- CoRIM need to upgrade dependent jwx package to a newer version
- Define CCA Specific Tagged values for Reference Values and Class Variables
- Cocli tool visual representation needs cocli corim submit sub command HOT 1
- Extend Eat to have the additional claims in EatCWTClaim HOT 1
- update `cocli` docs to reflect CoTS support
- Add CoSWID template
- Add Concise Evidence support
- Could owner give some requirements before build ? I have no idea where to start
- Visual Synopsis of the Available Commands diagram should appear sooner HOT 2
- merge the lint targets into one
- CCA "config ID" is not an identifier
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from corim.