How does this scheme compare with SWID? All common criteria protection profiles
are calling out for SWID tags. Rather than having to pay for the ISO standard,
NIST has a copy of nearly the same thing here:

The creation of SWID tags are expected to be done as part of the build
process. But there has to be some metadata that gets fed into build process to
cover things like product name, web site, license, etc.

It would be really good if we can align all of this to support SWID tag


