Open
Description
i.e., add property Signature CDXSignature
json:"signature,omitempty"to top-level
CDXBom` structure. Then support it with signing verification (validation) with testcases.
This will be a bit of a challenge as we may also need to implement JSF schema:
As referenced by the CycloneDX schema (external).
As we want the utility to work in a network-disconnected environment (e.g., a secure build pipeline), this would have to bring in a static encoding (marshal/unmarshal, etc.)