adoptium / temurin-build

Eclipse Temurin™ build scripts - common across all releases/versions
Apache License 2.0
1.02k stars 249 forks source link

Define SBoM use cases #3961

Open sxa opened 3 weeks ago

sxa commented 3 weeks ago

From today's secure dev call, we should look at the use cases for our SBoM files and decide which ones we wish to support, and then create follow-on work items to ensure we can support them.

Scanteianu commented 6 hours ago

I think ensuring that dependency-track can consume it and create artifacts (vdr/vex) would be a good thing to be able to do