Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing SBOM file #5466

Open
yashaswi2000 opened this issue Dec 5, 2023 · 0 comments
Open

Missing SBOM file #5466

yashaswi2000 opened this issue Dec 5, 2023 · 0 comments
Labels
a:docs Issue relates to documentation

Comments

@yashaswi2000
Copy link

Description

As part of the security self-assessment of emissary-ingress we performed(@yashaswi2000, @Disha-S-Gowda, @jcart657, @Saipv17), SBOM (Software Bill of Materials) file is found to be missing from the repository.

The open-source libraries, modules, and components that are used, together with their versions, are listed in an SBOM. This facilitates simpler updates/patching, makes it easier to detect susceptible components, and helps end users adhere to the terms of open-source licenses.

Expected Files

The repository should include a file meeting one of the following standards:

  • SPDX SBOM JSON
  • CycloneDX JSON/XML
  • SPDX SBOM Tag Value

Named sbom.json, bom.xml, sbom.spdx, etc. based on format.

Requested Info

Please update the repository with the relevant SBOM file. Please consider to include the following information:

  • SBOM file format standard used
  • Brief description of tools/process used to generate SBOM file
  • Link to SBOM documentation (if available)

This info helps users better understand and consume the SBOM content.

Other Relevant Info

Add any other info here.

@cindymullins-dw cindymullins-dw added the a:docs Issue relates to documentation label Dec 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
a:docs Issue relates to documentation
Projects
None yet
Development

No branches or pull requests

2 participants