github / github/dependency-submission-toolkit
Support SBOM as a submission format
オープン
enhancement
- 主要言語
- TypeScript
- スター
- 62
- フォーク
- 18
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
See discussion in https://github.com/orgs/github-community/discussions/18918 - it would be great if the toolkit could support SBOM standards out of the box, as this would enable a bridge from existing tooling into the github dependency submission api.
By leveraging existing standards you have a short way from existing standards into the new github features.
コントリビューションガイド
調査の方向性
リンクされた GitHub Community のディスカッションから始め、toolkit の既存の dependency snapshots 作成フローを、GitHub dependency submission API の要件と合わせて確認します。完了の条件は、具体的な SBOM 標準について合意し、それらの形式から有効な dependency submissions へ至る明確な経路を提示することです。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- github, typescript
- 領域
- api, security
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 25/100