kubernetes-sigs / kubernetes-sigs/cluster-api

Security Self-Assessment: [STRIDE-TAMPER-1] Produce a SBoM

Open
#6,153 32 comments 0 reactions 1 assignee Claimed by @jayesh-srivastava View on GitHub
area/security help wanted kind/feature priority/backlog sig/security triage/accepted
Dominant language
Go
Stars
4.3k
Forks
1.6k
Avg merge
1d 3h
Merged PRs (30d)
113

Description

**User Story**

As a cluster operator, i want to know the list of dependencies Cluster API brings for assurance within our organisation's software supply chain.

**Detailed Description**
* Create SBoM of all the Cluster API components and verify checksum as a post build action

cc @PushkarJ for adding more details.

/kind feature
/area security

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.