provenance data for all components of each software release (e.g., in a software bill of materials [SBOM]). Notional Implementation Examples(実装例): Example 1: Make the provenance data available to software acquirers in accordance with the organization’s policies, preferably using standards-based formats. (...) Example 4: Update the provenance data every time any of the software’s components are updated.
provenance data for all components of each software release (e.g., in a software bill of materials [SBOM]). ↓ 各ソフトウェアリリースのすべてのコンポーネントに対して, provenanceデータを収集(生成),保護,維持(保管),共有(配布)する