Open
Description
We should create a list of SBOMs we produce per SIG and keep the list updated. The idea isn't to track the individual releases, but to point users to the authoritative information about specific SBOMs. For instance, we know the Java SIG produces SBOMs for its core artifacts, so, we need to state which artifacts people can expect SBOMs to exist.