CycloneDX / CycloneDX/transparency-exchange-api

TEA publishing in various eco systems

Open
#73 0 comments 0 reactions 0 assignees View on GitHub
Open Source projects Publish
Dominant language
Shell
Stars
113
Forks
22
Avg merge
8d 12h
Merged PRs (30d)
5

Description

> Should we open issues to discuss how publishing to TEA would look for various ecosystems?
>
> As I stated before, a TEA publisher REST API is probably not required in the first TEA versions.
> For the Maven ecosystem I would expect TEA publishing to work as follows:
>
> 1. User publish artifacts with a `classifier` of `cyclonedx` or `sbom`, as they do now.
> 2. The Maven repository manager will expose those artifacts through some kind of additional TEA plugin. We probably should ask the main repository managers ([Sonatype Nexus](https://www.sonatype.com/products/sonatype-nexus-repository) and [JFrog](https://jfrog.com/)) how they feel about exporting the current repository metadata through TEA.
>
> Do we have any contacts with JFrog?

_Originally posted by @ppkarwasz in [#55](https://github.com/CycloneDX/transparency-exchange-api/issues/55#issuecomment-2482741690)_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.