github / github/roadmap

SBOM Export user interface and API support retrieval of dependency snapshots [GA]

Aperta
#1,273 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Enterprise Free GitHub Advanced Security (GHAS) Paused Team
Lingua principale
Nessun dato sulla lingua
Stelle
8.9k
Fork
1.8k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Value Prop
GitHub now lets you export and retrieve Software Bills of Materials (SBOMs,) including dependency snapshots, through both the UI and a fast, asynchronous API. Instead of generating SBOMs on demand (which was slow and subject to strict rate limits), SBOMs are now pre-stored for rapid retrieval, so you get reliable, consistent results even across large estates with tens of thousands of repositories. This makes it straightforward to integrate with third-party SCA tools, automate compliance reporting, and maintain internal audit records at scale.

### Expected Outcome
Enterprise customers managing large codebases have been unable to programmatically traverse their full repository estate for SBOMs due to synchronous API limitations, aggressive rate limits, and no guarantee of a response for any given request. With this release, we resolve those pain points by delivering a redesigned backend that supports asynchronous retrieval of pre-built SBOMs, including artifact and snapshot-level granularity. The expected outcomes are: (1) customers can reliably export SBOMs at scale without hitting availability issues, (2) integration with external compliance and SCA tooling becomes seamless, and (3) GitHub strengthens its position as the default platform for end-to-end supply chain security.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.