This library claims to implement the CycloneDX standard. And it doe.
but it also has some implementation parts that are not standard - they should be moved to the "contrib" area, or removed entirely.
Goal
Motivation:
- have a clean standard implementation, no opinionated fluff, only models and (de)serailization.