← Back to catalogue
Research draft

software

vr.tr.software · PHY.OBJ

Let an agent handle software by type, licence, security, supply chain, lifecycle and regulation, and support users and developers with sourced guidance.

Thing Registry Physical world and living systems

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify

Researched by: Claude

Purpose and description

Let an agent handle software by type, licence, security, supply chain, lifecycle and regulation, and support users and developers with sourced guidance.

Programs, data and instructions that tell a computer or device what to do, including system software such as operating systems, application software, firmware, libraries and services, distributed under licences and maintained through updates.

What it is for: Making computers and devices perform tasks.

It can be classify software and its licence; check security advisories and updates; understand software supply chain and SBOMs; find documentation and support.

Distinguishing features

Intangible instructions

Versioned and updated

Licensed rather than sold outright

Can contain vulnerabilities

What it looks like

Not physical; experienced through interfaces and represented by code and binaries.

How it is recognised

Programs, apps, libraries and firmware

Version numbers and licences

Hardware is the physical equipment

Related models

is a kind of - category

creative work and product

includes - kind

application software

runs on - platform

computer hardware

is distributed under - terms

software licence

In practice

Families and kinds

system software

application software

firmware

libraries and frameworks

open source and proprietary software

Identifiers

Package identifier purl or CPE software identity

Standards and regulation

EU Cyber Resilience Act

ISO/IEC 25010 software quality model

Medical device rules for software as a medical device

Failure modes and hazards

Security vulnerabilities

Licence non-compliance

End-of-life software without updates

Where this came from

wikidata · CC0 1.0

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.

Identify Which software.

Identity matters.

Type

Kind.

Type

Software type.

  1. Is this system software, an application, firmware or a library? definition
  2. Which version is installed? provenance

Licence

Terms.

Licence

Licence.

  1. Which licence applies, and what does it permit? provenance
  2. Is it compatible with the intended use? boundary
Security Vulnerabilities.

Security requires updates.

Advisories

CVEs.

Advisories

Security advisories.

  1. Are there known vulnerabilities for this version? provenance
  2. Is a patch available? provenance

Supply chain

Dependencies.

Supply chain

Supply chain.

  1. What does the software bill of materials list? provenance
  2. Are dependencies maintained? boundary
Lifecycle Support.

Software ages.

Support

End of life.

Support

Support lifecycle.

  1. When does support end for this version? provenance
  2. What migration path exists? action

Docs

Documentation.

Docs

Documentation.

  1. Where is the official documentation? provenance
  2. Is it current for this version? boundary
Regulation Rules.

Rules apply to some software.

Products

Product rules.

Products

Product rules.

  1. Which cybersecurity or product rules apply to this software? provenance
  2. Who is responsible as manufacturer? provenance

Critical

Safety-critical uses.

Critical

Safety-critical software.

  1. Is the software used in medical, automotive or other safety-critical settings? boundary
  2. Which standards govern it? provenance

What the second pass must settle

  • Should software types be separate entries?
  • How should identifiers such as purl be linked?
  • How should vulnerabilities be tracked?