heroku / heroku/roadmap

Software bill of materials (SBOM) generation as part of Heroku builds

Open
#21 2 comments 2 reactions 1 assignee Claimed by @ASayre View on GitHub
Buildpacks Security
Dominant language
No language data
Stars
225
Forks
19
PR merge metrics
No merged PRs in 30d

Description

As Heroku moves to Cloud-Native Buildpacks which [natively support generating a software bill of materials (SBOM)](https://buildpacks.io/docs/tools/pack/cli/pack_sbom_download/) artifact during the build process we'd like to capture this and surface it as metadata about the application, making it available via the API and CLI for fetching as needed.

We're also considering more advanced APIs that allow searching across SBOM data for multiple apps - but we'd like feedback on how it would be useful.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.