> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# AI Supply Chain Security to CylcloneDX Schema Mapping

The following table shows how Supply Chain fields are mapped to the CycloneDX 1.6 standard.

See [CycloneDX 1.6 JSON Reference](https://cyclonedx.org/docs/1.6/json/) for more information about the standard.

## Metadata

| Supply Chain v3 Output              | CycloneDX 1.6 Output                | Description                                                                                       |
| ----------------------------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------- |
| version                             | metadata.tools.components.version   | The version of a particular component used within a tool that generated or processed the AIBOM.   |
| inventory.model\_name               | metadata.component.name             | The name of the primary component that the AIBOM describes.                                       |
| inventory.model\_version            | metadata.component.version          | The version of the primary component that the AIBOM describes.                                    |
| inventory.requested\_scan\_location | metadata.component.properties.name  | The name of the property. Duplicate names are allowed, each potentially having a different value. |
| inventory.requested\_scan\_location | metadata.component.properties.value | The value of the property.                                                                        |
| status                              | metadata.properties.name            | The name of the property. Duplicate names are allowed, each potentially having a different value. |
| status                              | metadata.properties.value           | The value of the property.                                                                        |
| start\_time                         | metadata.properties.name            | The name of the property. Duplicate names are allowed, each potentially having a different value. |
| start\_time                         | metadata.properties.value           | The value of the property.                                                                        |
| end\_time                           | metadata.properties.name            | The name of the property. Duplicate names are allowed, each potentially having a different value. |
| end\_time                           | metadata.properties.value           | The value of the property.                                                                        |

## Components

A list of software and hardware components.

| Supply Chain v3 Output           | CycloneDX 1.6 Output        | Description                                                                                                                                                                                                                         |              |              |              |                   |
| -------------------------------- | --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------ | ------------ | ------------ | ----------------- |
| file\_results.file\_location     | components.name             | The name of the component. This will often be a shortened, single name of the component. Examples: **commons-lang3** and **jquery**.                                                                                                |              |              |              |                   |
| file\_results.file\_location     | components.bom-ref          | An optional identifier which can be used to reference the component elsewhere in the BOM. Every bom-ref must be unique within the BOM. Value SHOULD not start with the BOM-Link intro 'urn:cdx:' to avoid conflicts with BOM-Links. |              |              |              |                   |
| file\_results.details.sha256     | components.hashes.alg       | The algorithm that generated the SHA256 hash value.                                                                                                                                                                                 |              |              |              |                   |
| file\_results.details.sha256     | components.hashes.content   | The value of the SHA256 hash. Must match regular expression: \`^(\[a-fA-F0-9]                                                                                                                                                       | \[a-fA-F0-9] | \[a-fA-F0-9] | \[a-fA-F0-9] | \[a-fA-F0-9])$\`. |
| file\_results.details.md5        | components.hashes.alg       | The algorithm that generated the MD5 hash value.                                                                                                                                                                                    |              |              |              |                   |
| file\_results.details.md5        | components.hashes.content   | The value of the MD5 hash. Must match regular expression: \`^(\[a-fA-F0-9]                                                                                                                                                          | \[a-fA-F0-9] | \[a-fA-F0-9] | \[a-fA-F0-9] | \[a-fA-F0-9])$\`. |
| file\_results.details.file\_type | components.properties.name  | The name of the property. Duplicate names are allowed, each potentially having a different value.                                                                                                                                   |              |              |              |                   |
| file\_results.details.file\_type | components.properties.value | The value of the property.                                                                                                                                                                                                          |              |              |              |                   |
| file\_results.status             | components.properties.name  | The name of the property. Duplicate names are allowed, each potentially having a different value.                                                                                                                                   |              |              |              |                   |
| file\_results.status             | components.properties.value | The value of the property.                                                                                                                                                                                                          |              |              |              |                   |
| file\_results.details.tlsh       | components.properties.name  | The name of the property. Duplicate names are allowed, each potentially having a different value.                                                                                                                                   |              |              |              |                   |
| file\_results.details.tlsh       | components.properties.value | The value of the property.                                                                                                                                                                                                          |              |              |              |                   |

## Vulnerabilities

Vulnerabilities identified in components or services.

| Supply Chain v3 Output                          | CycloneDX 1.6 Output                   | Description                                                                                                                                                                                                                                                                  |
| ----------------------------------------------- | -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| file\_results.detections.rule\_id               | vulnerabilities.id                     | The identifier that uniquely identifies the vulnerability.                                                                                                                                                                                                                   |
| file\_results.detections.detection\_id          | vulnerabilities.bom-ref                | An optional identifier which can be used to reference the vulnerability elsewhere in the BOM. Every bom-ref must be unique within the BOM. Value SHOULD not start with the BOM-Link intro `urn:cdx:` to avoid conflicts with BOM-Links. Must be at least `1` character long. |
| file\_results.detections.category               | vulnerabilities.description            | A description of the vulnerability as provided by the source.                                                                                                                                                                                                                |
| file\_results.detections.description            | vulnerabilities.detail                 | If available, an in-depth description of the vulnerability as provided by the source organization. Details often include information useful in understanding root cause.                                                                                                     |
| file\_results.detections.severity               | vulnerabilities.ratings.severity       | Textual representation of the severity that corresponds to the numerical score of the rating.                                                                                                                                                                                |
| file\_results.detections.technical\_blog\_hrefs | vulnerabilities.advisories.url         | Location where the advisory can be obtained.                                                                                                                                                                                                                                 |
| file\_results.detections.cve                    | vulnerabilities.references.id          | An identifier that uniquely identifies the vulnerability. Example: "CVE-2021-39182"                                                                                                                                                                                          |
| file\_results.detections.cve                    | vulnerabilities.references.source      | The source that published the vulnerability.                                                                                                                                                                                                                                 |
| file\_results.detections.cve                    | vulnerabilities.references.source.name | The name of the source.                                                                                                                                                                                                                                                      |
| file\_results.detections.cve                    | vulnerabilities.references.source.url  | The url of the vulnerability documentation as provided by the source.                                                                                                                                                                                                        |
| file\_results.detections.owasp                  | vulnerabilities.references.id          | An identifier that uniquely identifies the vulnerability.                                                                                                                                                                                                                    |
| file\_results.detections.owasp                  | vulnerabilities.references.source      | The source that published the vulnerability.                                                                                                                                                                                                                                 |
| file\_results.detections.owasp                  | vulnerabilities.references.source.name | The name of the source.                                                                                                                                                                                                                                                      |
| file\_results.detections.owasp                  | vulnerabilities.references.source.url  | The url of the vulnerability documentation as provided by the source.                                                                                                                                                                                                        |
| file\_results.detections.mitre\_atlas           | vulnerabilities.references.id          | An identifier that uniquely identifies the vulnerability.                                                                                                                                                                                                                    |
| file\_results.detections.mitre\_atlas           | vulnerabilities.references.source      | The source that published the vulnerability.                                                                                                                                                                                                                                 |
| file\_results.detections.mitre\_atlas           | vulnerabilities.references.source.name | The name of the source.                                                                                                                                                                                                                                                      |
| file\_results.detections.mitre\_atlas           | vulnerabilities.references.source.url  | The url of the vulnerability documentation as provided by the source.                                                                                                                                                                                                        |
| file\_results.file\_location                    | vulnerabilities.affects.ref            | References a component or service by the objects bom-ref.                                                                                                                                                                                                                    |