apache / apache/airflow

Generate SBOM information for Airlfow Reference Images

Open
#34,239 3 comments 2 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
46.9k
Forks
17.8k
Avg merge
2d 7h
Merged PRs (30d)
484

Description

The SBOM information for the Airflow Reference Images should contain more information than just Python and Javascript - it should also include all the system dependencies that were used in the image. The CycloneDX tool that we are using should be able to produce such an information. and we shoudl even be able to embed the links to such published SBOMs with a (standard?) OCI label (and even retroactively update all the published images).

Contributor guide

Open the contributing guide

Research direction

Review the Airflow Reference Images build and publishing flow alongside the current CycloneDX output. The work is complete when SBOMs include system dependencies, published images expose links through an appropriate OCI label, and the requested existing images are addressed where feasible.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, javascript, python
Domain
devops, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.