assimp / assimp/assimp

[RFC] Assimp shall provide a SBOM for each release

Open
#5,974 1 comment 0 reactions 0 assignees View on GitHub
Feature-Request Security Risk
Dominant language
C++
Stars
13.2k
Forks
3.2k
Avg merge
2d 8h
Merged PRs (30d)
21

Description

**Is your feature request related to a problem? Please describe.**
The Asset-Importer-Lib is using a bundle of external libraries. If there are any kind of vulnerabilities in these we will not regcognize these.

**Describe the solution you'd like**
We shall generate an SBOM (Software Bill of Materials) to provide the versions for all used external software.

**Describe alternatives you've considered**
N/A

**Additional context**
My recommendation would be to offer the SBOS in CycloneX format.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing Assimp's release process and how its external libraries and versions are tracked. Define the release integration needed to generate a CycloneDX-format SBOM for every release, and verify that it lists all bundled external software with versions.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.