CycloneDX / CycloneDX/transparency-exchange-api
TEA publishing in various eco systems
- Dominant language
- Shell
- Stars
- 113
- Forks
- 22
- Avg merge
- 8d 12h
- Merged PRs (30d)
- 5
Description
> Should we open issues to discuss how publishing to TEA would look for various ecosystems?
>
> As I stated before, a TEA publisher REST API is probably not required in the first TEA versions.
> For the Maven ecosystem I would expect TEA publishing to work as follows:
>
> 1. User publish artifacts with a `classifier` of `cyclonedx` or `sbom`, as they do now.
> 2. The Maven repository manager will expose those artifacts through some kind of additional TEA plugin. We probably should ask the main repository managers ([Sonatype Nexus](https://www.sonatype.com/products/sonatype-nexus-repository) and [JFrog](https://jfrog.com/)) how they feel about exporting the current repository metadata through TEA.
>
> Do we have any contacts with JFrog?
_Originally posted by @ppkarwasz in [#55](https://github.com/CycloneDX/transparency-exchange-api/issues/55#issuecomment-2482741690)_
Contributor guide
Assessment
This issue has not been assessed yet.