Closed sjberman closed 1 year ago
Syft does not generate a full SBOM report with all transitive dependencies. FOSSA does, so we now use a custom script to generate the SBOM from a FOSSA report and upload to Azure when we release.
Syft does not generate a full SBOM report with all transitive dependencies. FOSSA does, so we now use a custom script to generate the SBOM from a FOSSA report and upload to Azure when we release.