Skip to content

Move CycloneDX Taxonomy to the GitLab docs

Why are we doing this work

In #366365 (closed), we created a CycloneDX property taxonomy and formally registered it with the CycloneDX project.

Since this document defines a contract similar to an API, we want changes to it to require approval from our team in order to prevent inadvertently breaking the contract. We initially chose to create an individual GitLab project to provide this control. However, creating new projects is discouraged unless necessary. We may be able to place this documentation inside the GitLab docs instead, and use a codeowners file in order require that changes be approved by our team.

Relevant links

Non-functional requirements

  • Documentation:
  • Feature flag:
  • Performance:
  • Testing:

Implementation plan

This is a specially controlled document which requires the use of codeowners to enforce extra control.

Verification steps

Edited by Alana Bellucci