kubernetes-sigs / bom

A utility to generate SPDX-compliant Bill of Materials manifests
https://kubernetes-sigs.github.io/bom/
Apache License 2.0
331 stars 48 forks source link

Support for SBOMs in (signed) in-toto attestations #441

Open puerco opened 4 months ago

puerco commented 4 months ago

What would you like to be added:

We should support reading and writing SBOMs in in-toto attestations. bom should be able to read SBOMs wrapped in in-toto attestations, even if they are wrapped in a DSSE Envelope or in sigstore bundles.

This requirement does not include signing and verifying the attestation signature.

Why is this needed:

Writing and reading the SBOM data from in-toto attestations will make bom a better companion to other supply chain tools by taking care of encoding/decoding the JSON matryoshka.

k8s-triage-robot commented 1 month ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot commented 1 week ago

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle rotten