CycloneDX / transparency-exchange-api

A standard API specification for exchanging supply chain artifacts and intelligence
https://tc54.org/
Apache License 2.0
59 stars 9 forks source link

Document TEA usage for Open Source projects #54

Open oej opened 1 month ago

oej commented 1 month ago

We have so far focused a lot on "manufacturers" but Open Source projects can be more open, have SBOMs in an open file store and still need discovery and automatic distribution

oej commented 1 month ago

A question I got was if the SBOM files and artefacts can be stored on a regular file system (like a web server) anywhere.

oej commented 4 weeks ago

We need to investigate various packaging systems and find out their position on distribution of SBOMs