CycloneDX / CycloneDX/cyclonedx-python

feat: include `component.evidence.identity` in the SBOM

Đang mở
#829 1 bình luận 1 reaction 0 người được giao Xem trên GitHub
enhancement hacktoberfest help wanted
Ngôn ngữ chính
Python
Star
390
Fork
98
Merge trung bình
2 ngày 23 giờ
Pull request đã merge (30 ngày)
2

Mô tả

## Is your feature request related to a problem? Please describe.

Establishing accurate component identity is important in an SBOM, as it enables users to clearly understand how each component's identity was determined and the methods applied in this process.

## Describe the solution you'd like

By including Component's `.evidence.identity` within the SBOM, we provide transparency on the techniques and data sources used to verify component identity, enhancing both the reliability and trustworthiness of the SBOM.

https://cyclonedx.org/docs/1.6/json/#components_items_evidence_identity

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

The issue names no implementation files or tests. Start by tracing where components are serialized into the SBOM, then compare the output with the linked CycloneDX 1.6 definition for components.evidence.identity. Done means generated SBOM output includes the requested identity evidence.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
devtools, security
Loại issue
Tính năng
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.