Open mayaCostantini opened 2 years ago
/sig stack-guidance /priority important-soon
Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale
.
Stale issues rot after an additional 30d of inactivity and eventually close.
If this issue is safe to close now please do so with /close
.
/lifecycle stale
/remove-lifecycle stale /lifecycle frozen
Is your feature request related to a problem? Please describe.
As a user of the Thoth Adviser GitHub action, I would like to get a Software Bill Of Materials of my dependencies at the end of the dependency analysis.
Describe the solution you'd like
An option would be to use the anchore/sbom-action on the analyzed repository to optionally generate an SBOM with the dependencies of the project, or any suitable action capable to generate SBOMs.