CISA-SBOM-Community / SBOM-Generation

Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team
Apache License 2.0
16 stars 4 forks source link

Phase-1 Ecosystem Improvement Tracking #32

Open idunbarh opened 1 month ago

idunbarh commented 1 month ago

This issue is used to keep a running list of issues we create on projects used within phase 1.

Please include links to issues this team creates.

idunbarh commented 1 month ago

https://github.com/aquasecurity/trivy/discussions/7626 - request to generate multiple SBOM documents in different formats from a single call of trivy.

VinodAnandan commented 1 month ago

https://github.com/kubernetes-sigs/bom/issues/100 - Request to provide support for CycloneDX

VinodAnandan commented 1 month ago

https://github.com/fluxcd/flux2/discussions/2430 - Request to publish CycloneDX SBOM

vpetersson commented 1 month ago

fluxcd/flux2#2430 - Request to publish CycloneDX SBOM

I can have a chat with the ControlPlane guys, but it really is just a switch that needs to be added. Thus I'm not sure this is a good project for this group.

tiegz commented 1 month ago

https://github.com/snyk/parlay/pull/78 - @goneall 's PR to add supplier data to parlay

idunbarh commented 4 weeks ago

https://github.com/anchore/syft/issues/3397 answering the request from Josh to create an issue on the syft repo to merge sbom generation and augmentation.

vpetersson commented 3 weeks ago