CycloneDX / CycloneDX/specification
[ENHANCEMENT] Investigate OmniBOR (aka gitbom) integration
Open
- Dominant language
- XSLT
- Stars
- 547
- Forks
- 93
- Avg merge
- 7h 11m
- Merged PRs (30d)
- 37
Description
gitbom is a minimal specification to generate an artifact tree and a unique identifier for an artifact that is metadata agnostic and only depends on the artifact byte contents. If adopted widely and integrated with build tools, it can potentially solve some interesting problems https://gitbom.dev/glossary/sbom/#gitbom-compliments-sbom
Should we consider adding fields in the 1.5 cyclonedx schema to support gitbom ids and documents?
Relevant links - https://gitbom.dev/
Contributor guide
Assessment
This issue has not been assessed yet.