Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update SBOM build information #15

Closed
wants to merge 1 commit into from

Conversation

vargenau
Copy link
Collaborator

Signed-off-by: Marc-Etienne Vargenau marc-etienne.vargenau@nokia.com

Signed-off-by: Marc-Etienne Vargenau <marc-etienne.vargenau@nokia.com>
Copy link
Collaborator

@Jimmy-ahlberg Jimmy-ahlberg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WE need to have a much bigger conversation on WHEN is an SBOM created, the current wording is unclear and creates obligations with much uncertainty.

@winterrocks
Copy link

I'm not sure if it is possible to mandate all vendors to create SBOM at some time. But likely build time is the best?

@stephenkilbaneadi
Copy link
Contributor

Oh, every vendor has to create an SBOM at some time - no vendor will create one at no time. :-)

But this isn't about requiring that all vendors create the SBOM at the same point in the build process, but that they record in the SBOM the choice the vendor made.

@eaglei15
Copy link

eaglei15 commented Dec 2, 2022

6CFEF42E-61DA-4ED9-87DF-BB03E1298143

@vargenau vargenau closed this Apr 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants