microsoft / microsoft/sbom-tool

[Microsoft.Sbom.Targets] Add target for publish

Open
#983 6 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

.NET tabled
Dominant language
C#
Stars
2.1k
Forks
201
Avg merge
6d 21h
Merged PRs (30d)
1

Description

Hello everyone,

we are currently using Microsoft.Sbom.Targets to generate SBOMs for our applications. However, we have encountered a limitation where Microsoft.Sbom.Targets only provides a target for dotnet pack.

To better support our workflow, we would like to request the addition of a target for dotnet publish. This would enable us to generate SBOMs for non-NuGet packages as well and simplify our pipelines.

The output should be the same as using the SBOM tool directly.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Microsoft.Sbom.Targets implementation for the existing dotnet pack target and the entry point used by dotnet publish. Determine how a publish target should invoke SBOM generation for non-NuGet packages, then verify that its output matches using the SBOM tool directly.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
build-system
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.