github / github/roadmap

SBOM Export user interface and API support retrieval of dependency snapshots [GA]

Ouverte
#1,273 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Enterprise Free GitHub Advanced Security (GHAS) Paused Team
Langage dominant
Aucune donnée de langage
Étoiles
8.9k
Forks
1.8k
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

### Value Prop
GitHub now lets you export and retrieve Software Bills of Materials (SBOMs,) including dependency snapshots, through both the UI and a fast, asynchronous API. Instead of generating SBOMs on demand (which was slow and subject to strict rate limits), SBOMs are now pre-stored for rapid retrieval, so you get reliable, consistent results even across large estates with tens of thousands of repositories. This makes it straightforward to integrate with third-party SCA tools, automate compliance reporting, and maintain internal audit records at scale.

### Expected Outcome
Enterprise customers managing large codebases have been unable to programmatically traverse their full repository estate for SBOMs due to synchronous API limitations, aggressive rate limits, and no guarantee of a response for any given request. With this release, we resolve those pain points by delivering a redesigned backend that supports asynchronous retrieval of pre-built SBOMs, including artifact and snapshot-level granularity. The expected outcomes are: (1) customers can reliably export SBOMs at scale without hitting availability issues, (2) integration with external compliance and SCA tooling becomes seamless, and (3) GitHub strengthens its position as the default platform for end-to-end supply chain security.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.