CycloneDX / CycloneDX/cyclonedx-python
feat: mark SBOM from `requirements` as "incomplete"
- Lingua principale
- Python
- Stelle
- 390
- Fork
- 98
- Merge medio
- 2g 23h
- PR unite (30g)
- 2
Descrizione
## Is your feature request related to a problem? Please describe.
when generating an SBOM from a requirements.txt, it is currently not planned to pull transitive depednencies.
therefore, the SBOM might be incomplete.
this shall eb stated via CycloneDX `compositition`
## Describe the solution you'd like
when generating an SBOM from a `requirements.txt`,
for the rtoot component: the dependency composition completeness is set to "incomplete_first_party_only" - see https://cyclonedx.org/guides/OWASP_CycloneDX-Authoritative-Guide-to-SBOM-en.pdf page 59
also: add a CLI flag to set this value according to spec - https://cyclonedx.org/docs/1.6/json/#compositions_items_aggregate
## Describe alternatives you've considered
/
## Additional context
/
## Contribution
- [ ] I am willing to provide an implementation
- [x] I will wait until somebody else implements it
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.