github / github/roadmap

SBOM Export user interface and API support retrieval of dependency snapshots [GA]

未关闭
#1,273 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Enterprise Free GitHub Advanced Security (GHAS) Paused Team
主要语言
没有语言数据
星标
8.9k
派生
1.8k
PR 合并指标
30 天内没有已合并 PR

描述

### Value Prop
GitHub now lets you export and retrieve Software Bills of Materials (SBOMs,) including dependency snapshots, through both the UI and a fast, asynchronous API. Instead of generating SBOMs on demand (which was slow and subject to strict rate limits), SBOMs are now pre-stored for rapid retrieval, so you get reliable, consistent results even across large estates with tens of thousands of repositories. This makes it straightforward to integrate with third-party SCA tools, automate compliance reporting, and maintain internal audit records at scale.

### Expected Outcome
Enterprise customers managing large codebases have been unable to programmatically traverse their full repository estate for SBOMs due to synchronous API limitations, aggressive rate limits, and no guarantee of a response for any given request. With this release, we resolve those pain points by delivering a redesigned backend that supports asynchronous retrieval of pre-built SBOMs, including artifact and snapshot-level granularity. The expected outcomes are: (1) customers can reliably export SBOMs at scale without hitting availability issues, (2) integration with external compliance and SCA tooling becomes seamless, and (3) GitHub strengthens its position as the default platform for end-to-end supply chain security.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。