Skip to content

[Improvement] Require a procedure to create a SBOM #112

@kappapiana

Description

@kappapiana

Describe the improvement

Policy template: require a procedure to make a SBOM for each distribution artifact

Additional context

Section 3.3.1 requires that a SBOM is made, but under that heading the policy language does not require the existence of a procedure to create a SBOM. I believe that -- while an actual SBOM is not required for conformance -- having a procedure that mandates its creation before distribution is.

Consulting with @andrewjskatz I have added language he suggests in a PR that is linked to this issue.

Apart from accepting the PR, I suggest that these steps are required:

  • align the Excel file
  • align the ODS file
  • align the Markdown example generic policy text.

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions