anchore / anchore/syft

hash integrity of the scanned image

Open
#451 5 comments 1 reaction 0 assignees View on GitHub
enhancement format:cyclonedx
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
1d 5h
Merged PRs (30d)
42

Description

**What would you like to be added**: Add integrity verification to SBOMs ref: https://cyclonedx.org/use-cases/#integrity-verification

**Why is this needed**:
This is beneficial to verify the integrity of the image via multiple supported methods.

**Additional context**:

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start with the linked CycloneDX integrity-verification use case and review how Syft represents SBOMs for container images; done should include defined supported verification methods and integrity information in the generated SBOMs.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.