

Specifies the type of an external identifier.


ExteralIdentifierType specifies the type of an external identifier.



Name ExternalIdentifierType


  • cpe22: https://cpe.mitre.org/files/cpe-specification_2.2.pdf
  • cpe23: https://nvlpubs.nist.gov/nistpubs/Legacy/IR/nistir7695.pdf
  • cve: An identifier for a specific software flaw defined within the official CVE Dictionary and that conforms to the CVE specification as defined by https://csrc.nist.gov/glossary/term/cve_id.
  • email: https://datatracker.ietf.org/doc/html/rfc3696#section-3
  • gitoid: https://www.iana.org/assignments/uri-schemes/prov/gitoid Gitoid stands for Git Object ID and a gitoid of type blob is a unique hash of a binary artifact. A gitoid may represent the software Artifact ID or the OmniBOR Identifier for the software artifact's associated OmniBOR Document; this ambiguity exists because the OmniBOR Document is itself an artifact, and the gitoid of that artifact is its valid identifier. Omnibor is a minimalistic schema to describe software Artifact Dependency Graphs. Gitoids calculated on software artifacts (Snippet, File, or Package Elements) should be recorded in the SPDX 3.0 SoftwareArtifact's ContentIdentifier property. Gitoids calculated on the OmniBOR Document (OmniBOR Identifiers) should be recorded in the SPDX 3.0 Element's ExternalIdentifier property.
  • other: Used when the type doesn't match any of the other options.
  • packageUrl: https://github.com/package-url/purl-spec
  • securityOther: Used when there is a security related identifier of unspecified type.
  • swhid: SoftWare Hash IDentifier, persistent intrinsic identifiers for digital artifacts, such as files, trees (also known as directories or folders), commits, and other objects typically found in version control systems. The syntax of the identifiers is defined in the SWHID specification and they typically look like swh:1:cnt:94a9ed024d3859793618152ea559a168bbcbb5e2.
  • swid: https://www.ietf.org/archive/id/draft-ietf-sacm-coswid-21.html#section-2.3
  • urlScheme: the scheme used in order to locate a resource https://www.iana.org/assignments/uri-schemes/uri-schemes.xhtml