Open tschmidtb51 opened 3 days ago
@tschmidtb51 Thanks for bringing this to our attention. I think we need to wait until this line in the go.mod is updated, before making the change to the attribution file.
Waiting for https://github.com/gocsaf/csaf/pull/585 to merge.
What would you like to be added:
Update the repo reference, if applicable.
Why is this needed: For your awareness:
As the tools are not a PoC (even since the first release), the long overdue change was conducted: The repo https://github.com/csaf-poc/csaf_distribution moved to https://github.com/gocsaf/csaf. The old URL can still be used for a couple month before it is sunsetted for security reasons. Also, the license changed from MIT to Apache 2.0 (on the main branch, there is no new release yet).
Currently, that is mentioned e.g. in https://github.com/aws/eks-anywhere-build-tooling/blob/main/projects/aquasecurity/trivy/ATTRIBUTION.txt#L149-L150