Skip to main content

Specifications

These are specifications that have adopted PURL or VERS as part of a specification.

Ecma TC54-TG3 is chartered with the standardization of the Common Lifecycle Enumeration (CLE), an open specification designed to support the aliasing of components and communicate lifecycle events such as end-of-life (EOL), end-of-support (EOS), and changes in component provenance over time.
  • StandardsVERS
A language to exchange Security Advisories.
  • StandardsVERS
The CVE Record Format is the JSON schema defining the structure of CVE records.
  • LicenseCC0 1.0 Universal
  • StandardsPURL v1.0
A lightweight software bill-of-material (SBOM) specification.
  • LicenseApache-2.0
  • StandardsPURL v1.0, VERS
An implementation of the Vulnerability Exploitability Exchange (VEX for short) that is designed to be minimal, compliant, interoperable, and embeddable.
  • LicenseCC0-1.0
  • StandardsPURL v1.0
Open Source Vulnerability Schema.
  • LicenseApache-2.0
  • StandardsPURL v1.0
A data exchange standard for human-readable and machine-processable software bill-of-materials (SBOM).
  • LicenseCommunity-Spec-1.0, CC-BY-3.0
  • StandardsPURL v1.0