CycloneDX / CycloneDX/specification

[ENHANCEMENT] Investigate OmniBOR (aka gitbom) integration

Open
#131 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
XSLT
Stars
547
Forks
93
Avg merge
7h 11m
Merged PRs (30d)
37

Description

gitbom is a minimal specification to generate an artifact tree and a unique identifier for an artifact that is metadata agnostic and only depends on the artifact byte contents. If adopted widely and integrated with build tools, it can potentially solve some interesting problems https://gitbom.dev/glossary/sbom/#gitbom-compliments-sbom

Should we consider adding fields in the 1.5 cyclonedx schema to support gitbom ids and documents?

Relevant links - https://gitbom.dev/

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.