JimFuller-RedHat / sbomsleuth

Generate sbom quality report
Apache License 2.0
3 stars 0 forks source link

structure specific rulesets #1

Open JimFuller-RedHat opened 6 days ago

JimFuller-RedHat commented 6 days ago

from anonymous - 'I'd want to have smarter checks that understand the composition of our software too though. For example, every RPM manifest should have an SRPM package and a set of binary, arch-specific RPMs that are generated from that SRPM. That can't be checked by just validating certain fields exists but understanding the overall structure.'

having these grouped into declarative rulesets (ex.redhat, debian) might be handy

JimFuller-RedHat commented 6 days ago

https://redhatproductsecurity.github.io/security-data-guidelines/sbom/#document-structure