Attested SBOMs associated with artifacts are now visible in a repository's dependency graph [GA]
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 8.9k
- Fork
- 1.8k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
### Value Prop
Organizations need full visibility into the software dependencies behind every release—not just what's on the default branch today. With attested SBOMs now surfaced in the dependency graph, customers can inspect the exact dependency tree associated with any artifact, giving them a trustworthy, point-in-time view of what shipped. This strengthens supply-chain security posture, supports compliance and audit workflows, and builds confidence that dependency data is accurate and tamper-evident through attestation.
### Expected Outcome
Enable customers to store, view, and act on multiple dependency graph snapshots—not just the tip of the default branch. This is critical for teams maintaining long-term-support (LTS) releases or long-running production deployments, where newly-disclosed vulnerabilities against historical dependency trees represent real risk. By making attested SBOMs visible in the dependency graph, we lay the foundation for historical vulnerability alerting and give security teams the tools to assess and remediate risk across every release they support.
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.