ossf / tac

Technical Advisory Council
https://openssf.org
Other
108 stars 53 forks source link

Share OSSF project inventory with downstream consumers for incident response #306

Closed sevansdell closed 4 months ago

sevansdell commented 5 months ago

After all the projects are done self-identifying the initial stage they are in, I propose we adjust the incubating project lifecycle to post an SBOM on their github repo, maintain updating it with some frequency, and include a purl for software identification.

sevansdell commented 4 months ago

Closing due to lack of progress.