aboutcode-org / aboutcode-org/www.aboutcode.org

POST: SBOM signature, schmignature

Offen
#28 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
blog ready-to-post
Vorherrschende Sprache
JavaScript
Sterne
9
Forks
18
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

There is a school of thoughts that SBOMs are at risk and can be scammed, spoofed and tempered with and that will be the end of the world.

The quality of inventories collected by SCA tools is the problem.

I appreciate the concern wrt. SBOM integrity, but frankly I feel that that concern of hacking or spoofing an SBOM is a red herring and the least of concerns in the current state of affairs.

I can happily sign an incorrect SBOM and recipients will get the warm and fuzzies from my signature. But the data can still be wrong. The concern is to get correct tools, with verifiable reporting and detection capabilities backed by open, community-driven benchmarks so I can get some comfort that the tool has basic features.

Until then, signing is mostly harmless and the addiction to signing and checksumming everything from SBOM to attestations - including bad data - as being the cure-it-all to software supply chain issues is not a solution but a distraction in most cases until we have reached more tooling maturity.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.