Attested SBOMs associated with artifacts are now visible in a repository's dependency graph [GA]
- 主要言語
- 言語のデータがありません
- スター
- 8.9k
- フォーク
- 1.8k
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
### Value Prop
Organizations need full visibility into the software dependencies behind every release—not just what's on the default branch today. With attested SBOMs now surfaced in the dependency graph, customers can inspect the exact dependency tree associated with any artifact, giving them a trustworthy, point-in-time view of what shipped. This strengthens supply-chain security posture, supports compliance and audit workflows, and builds confidence that dependency data is accurate and tamper-evident through attestation.
### Expected Outcome
Enable customers to store, view, and act on multiple dependency graph snapshots—not just the tip of the default branch. This is critical for teams maintaining long-term-support (LTS) releases or long-running production deployments, where newly-disclosed vulnerabilities against historical dependency trees represent real risk. By making attested SBOMs visible in the dependency graph, we lay the foundation for historical vulnerability alerting and give security teams the tools to assess and remediate risk across every release they support.
コントリビューションガイド
評価
この issue はまだ評価されていません。