snyk / parlay

Enrich SBOMs with data from third party services
Apache License 2.0
124 stars 19 forks source link

Add enrichment using the Scorecards API #2

Closed garethr closed 1 year ago

garethr commented 1 year ago

The OpenSSF Scorecards project now has an API. Needs some discussion of how best to add Scorecard data to an SBOM.

Some conversation in the context of CycloneDX in the CycloneDX Slack. The new annotations in the upcoming v1.5 look like the best option.

garethr commented 1 year ago

Closed in #13