Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cyclonedx-library in bom.metadata.tools #637

Closed
jkowalleck opened this issue Feb 16, 2023 · 1 comment
Closed

cyclonedx-library in bom.metadata.tools #637

jkowalleck opened this issue Feb 16, 2023 · 1 comment
Labels
enhancement New feature or request

Comments

@jkowalleck
Copy link
Member

Is your feature request related to a problem? Please describe.

Current SBOM result contains the tool that was used to gather all data.

But it did not include the cyclonedx-library, which does data model transformations/serializations and in the end produces the SBOM result.
Therefore, it is not entirely clear, HOW a SBOM was created - in terms of reproducibility.

Describe the solution you'd like

have the cyclonedx-library in bom.metadata.tools[], with the library's name, version, and references to download/sources

Describe alternatives you've considered

none

Additional context

none

@jkowalleck jkowalleck added the enhancement New feature or request label Feb 16, 2023
@jkowalleck
Copy link
Member Author

closed via #638

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant