odpi / egeria

Egeria core
https://egeria-project.org
Apache License 2.0
812 stars 261 forks source link

Generate SBOMs for Egeria (all repos) #6621

Open planetf1 opened 2 years ago

planetf1 commented 2 years ago

Is there an existing issue for this?

Please describe the new behavior that that will improve Egeria

SBOMs (Software Bill of Materials) can include information about

Alternatives

No response

Any Further Information?

No response

Would you be prepared to be assigned this issue to work on?

planetf1 commented 2 years ago

Observation: Sonatype Life (which scans our code) can generate CycloneDX SBOMs with vulnarability information. See https://lift.sonatype.com/results/github.com/odpi/egeria/01G5PTAEMBCH6PTJ4F8GFTVQAV?tab=dependencies

Screenshot 2022-06-17 at 11 54 16
github-actions[bot] commented 2 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 20 days if no further activity occurs. Thank you for your contributions.

github-actions[bot] commented 2 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 20 days if no further activity occurs. Thank you for your contributions.

github-actions[bot] commented 1 year ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 20 days if no further activity occurs. Thank you for your contributions.

planetf1 commented 1 year ago

See also https://github.blog/2023-03-28-introducing-self-service-sboms/ & referenced actions