CycloneDX / CycloneDX/cyclonedx-gomod

No Author information in SBOM

Open
#388 2 comments 2 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
187
Forks
40
Avg merge
1d 7h
Merged PRs (30d)
14

Description

The SBOM generated does not add Author information which is one of the required baseline attributes described in the NTIA guidelines. I've seen other SBOM tools handle this by accepting a command line parameter to describe the Author organization which is then included in the resulting SBOM.

Is there some way of doing the same using cyclonedx-gomod?

Contributor guide

Open the contributing guide

Research direction

No files or tests are named in the issue. Start by locating the command-line option definitions and the SBOM output-generation path, then trace how component metadata is serialized. Done means an author organization can be supplied through the CLI and appears in the generated SBOM as required by the NTIA baseline.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.