software
Let an agent handle software by type, licence, security, supply chain, lifecycle and regulation, and support users and developers with sourced guidance.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify
Researched by: Claude
Purpose and description
Let an agent handle software by type, licence, security, supply chain, lifecycle and regulation, and support users and developers with sourced guidance.
Programs, data and instructions that tell a computer or device what to do, including system software such as operating systems, application software, firmware, libraries and services, distributed under licences and maintained through updates.
What it is for: Making computers and devices perform tasks.
It can be classify software and its licence; check security advisories and updates; understand software supply chain and SBOMs; find documentation and support.
Distinguishing features
Intangible instructions
Versioned and updated
Licensed rather than sold outright
Can contain vulnerabilities
What it looks like
Not physical; experienced through interfaces and represented by code and binaries.
How it is recognised
Programs, apps, libraries and firmware
Version numbers and licences
Hardware is the physical equipment
Related models
is a kind of - category
includes - kind
runs on - platform
is distributed under - terms
In practice
Families and kinds
system software
application software
firmware
libraries and frameworks
open source and proprietary software
Identifiers
Package identifier purl or CPE software identity
Standards and regulation
EU Cyber Resilience Act
ISO/IEC 25010 software quality model
Medical device rules for software as a medical device
Failure modes and hazards
Security vulnerabilities
Licence non-compliance
End-of-life software without updates
Where this came from
wikidata · CC0 1.0
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.
Identify Which software.
Identity matters.
Type
Kind.
Type
Software type.
- Is this system software, an application, firmware or a library? definition
- Which version is installed? provenance
Licence
Terms.
Licence
Licence.
- Which licence applies, and what does it permit? provenance
- Is it compatible with the intended use? boundary
Security Vulnerabilities.
Security requires updates.
Advisories
CVEs.
Advisories
Security advisories.
- Are there known vulnerabilities for this version? provenance
- Is a patch available? provenance
Supply chain
Dependencies.
Supply chain
Supply chain.
- What does the software bill of materials list? provenance
- Are dependencies maintained? boundary
Lifecycle Support.
Software ages.
Support
End of life.
Support
Support lifecycle.
- When does support end for this version? provenance
- What migration path exists? action
Docs
Documentation.
Docs
Documentation.
- Where is the official documentation? provenance
- Is it current for this version? boundary
Regulation Rules.
Rules apply to some software.
Products
Product rules.
Products
Product rules.
- Which cybersecurity or product rules apply to this software? provenance
- Who is responsible as manufacturer? provenance
Critical
Safety-critical uses.
Critical
Safety-critical software.
- Is the software used in medical, automotive or other safety-critical settings? boundary
- Which standards govern it? provenance
What the second pass must settle
- Should software types be separate entries?
- How should identifiers such as purl be linked?
- How should vulnerabilities be tracked?