Attested SBOMs associated with artifacts are now visible in a repository's dependency graph [GA]
- Lenguaje dominante
- Sin datos de lenguaje
- Estrellas
- 8.9k
- Forks
- 1.8k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
### Value Prop
Organizations need full visibility into the software dependencies behind every release—not just what's on the default branch today. With attested SBOMs now surfaced in the dependency graph, customers can inspect the exact dependency tree associated with any artifact, giving them a trustworthy, point-in-time view of what shipped. This strengthens supply-chain security posture, supports compliance and audit workflows, and builds confidence that dependency data is accurate and tamper-evident through attestation.
### Expected Outcome
Enable customers to store, view, and act on multiple dependency graph snapshots—not just the tip of the default branch. This is critical for teams maintaining long-term-support (LTS) releases or long-running production deployments, where newly-disclosed vulnerabilities against historical dependency trees represent real risk. By making attested SBOMs visible in the dependency graph, we lay the foundation for historical vulnerability alerting and give security teams the tools to assess and remediate risk across every release they support.
Guía de contribución
Evaluación
Este issue todavía no se ha evaluado.