The stable identity of the product as an offering, independent of any single release, package or deployment.
product-identity-record
Product Identity Record
The authoritative record that fixes the product's master-system identifier, canonical name, issuing namespace, producer of record and the criterion separating it from adjacent offerings.
Questions
- Which identifier is the authoritative master-system identifier for this product, and which system issued it?identity
Expected answer
- issuing system name
- identifier value
- identifier scheme reference
- assignment timestamp
- Within which namespace is the canonical product name unique, and which marketing or legacy names alias it?definition
Expected answer
- canonical name
- namespace reference
- alternate and legacy names
- Which organization is accountable as producer or supplier of record for this product?ownership
Expected answer
- producer organization reference
- role code (producer, supplier, distributor)
- accountability start time
- Where does this product stop, and which adjacent offerings are separate products rather than editions of this one?composition
Expected answer
- sibling product references
- edition list
- stated separation criterion
Artifacts
- Product identity cardThe canonical record instance carrying the master key, namespace, canonical and alternate names, producer reference and separation criterion.
identifier-coordinates-and-crosswalk
Identifier Coordinates and Crosswalk
Ecosystem-facing coordinates that let external systems match this product and its releases (Package URL, CPE, SWID, download location, content identifiers), plus the mapping and precedence between them.
Questions
- What Package URL type, namespace, name and qualifiers identify the distributed form of this product?identity
Expected answer
- purl type
- purl namespace and name
- qualifier set
- canonical purl string
- Which CPE names are asserted to denote this product, and who asserted them?interoperability
Expected answer
- CPE name
- dictionary status
- asserting party
- assertion time
- Where two identifier schemes disagree about the product boundary, which scheme is authoritative for which use?decision
Expected answer
- use case
- authoritative scheme
- precedence rationale
- How is a claimed coordinate verified against the published artifact before it is trusted?validation
Expected answer
- verification method
- verifier identity
- verification outcome
Artifacts
- Identifier crosswalk tableMapping between the product master key and each external coordinate, with asserting party, validity window and precedence for matching.
product-family-edition-and-sku
Family, edition, channel and SKU
CoSWID software-meta separates product, product-family, edition, channel-type, colloquial-version and revision from the exact software-version. CSAF product trees use vendor/product/version branches, product groups and relationships among products. These group commercial variants (enterprise versus standard, OEM versus academic, LTS line) without treating each SKU as an unrelated product or collapsing them into a single version.
Questions
- Which product family, edition and colloquial version line does this offering belong to, and which sibling editions share the same code base?composition
Expected answer
- product-family
- edition
- colloquial-version
- Which distribution or licensing channel (OEM, academic, retail, volume or other) applies to this offering?classification
Expected answer
- Which CSAF product group, if any, collects this product with related products for common advisory or remediation status?relationship
Expected answer
Artifacts
- Product tree branchFamily/edition/channel branch locating this offering inside a producer product tree.