?um/p1-90`For the purposes of this document, the following terms and definitions apply. Terms explicitly defined in this Standard are not to be presumed to refer implicitly to similar terms defined elsewhere.
formal declaration that something is true or accurate
Attestations are often backed by documentation or verification from an authoritative source. An attestation serves as a confirmation or proof of a fact, condition, or compliance with specific standards or requirements.
person who creates written works, such as software or data
purpose for which a software component exists
Examples of component functions include parsers, database persistence, and authentication providers.
general classification of a software components architecture
Examples of component types include libraries, frameworks, applications, containers, and operating systems.
entity that develops and produces products such as virtual or physical goods
component that is referenced by a main (metadata) component itself
ecosystem-agnostic specification which standardizes the syntax and location information of software components
data which describes the lineage and/or process for which software has been created or altered
process of agreeing to terms and acquiring physical or virtual goods or services
chain of custody and origin of a software component
Provenance incorporates the point of origin through distribution as well as derivatives in the case of software that has been modified.
entity that offers services, infrastructure, or platforms
These services can include computing resources, storage, software applications, and networking capabilities.
entity that produces and distributes content, such as software, to the public
ISO standard that formalizes XML records that uniquely identify software products, versions, and installations to support asset management, security, and compliance
Linux Foundation project which produces a standardized list of open source licences and defines an expression language for those licences
entity that provides products or services to another entity, typically within a supply chain
software component not directly created
Third-party components may include open source, "source available", and commercial or proprietary software.
software component that is indirectly used by another component by means of being a dependency of a dependency