aquasecurity / chain-bench

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
Apache License 2.0
717 stars 62 forks source link

Add sonatype as SBOM generator #14

Closed davidsalame1 closed 2 years ago

davidsalame1 commented 2 years ago

Description

sonatype has an SBOM generation tool called "jake", it should be one of the SBOM tools.

Checklist

CLAassistant commented 2 years ago

CLA assistant check
All committers have signed the CLA.