CycloneDX / CycloneDX/cyclonedx-gomod
No Author information in SBOM
- Dominant language
- Go
- Stars
- 187
- Forks
- 40
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 14
Description
The SBOM generated does not add Author information which is one of the required baseline attributes described in the NTIA guidelines. I've seen other SBOM tools handle this by accepting a command line parameter to describe the Author organization which is then included in the resulting SBOM.
Is there some way of doing the same using cyclonedx-gomod?
Contributor guide
Research direction
No files or tests are named in the issue. Start by locating the command-line option definitions and the SBOM output-generation path, then trace how component metadata is serialized. Done means an author organization can be supplied through the CLI and appears in the generated SBOM as required by the NTIA baseline.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100