Some minor technicalities:
- If we are including an explicit list of SBOM paths, I think we should also include a
Content-Typefor every file (much like we have forDescription) that would indicate the specific file format. - If we are not forcing a specific SBOM standard, then I don’t think we should be enforcing JSON format.