-
Notifications
You must be signed in to change notification settings - Fork 23
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Secure Software Supply Chain Aspects #132
Comments
afrittoli
added a commit
to afrittoli/cdevents-spec
that referenced
this issue
Nov 25, 2023
Artifact packaged and/or published events may include a link to a published SBOM. Since there is no default storage location for such SBOM documents, CDEvents may help linking the artifact with its SBOM by including a link to the SBOM in the artifact events. Partially-addresses: cdevents#132 Signed-off-by: Andrea Frittoli <andrea.frittoli@gmail.com>
4 tasks
afrittoli
added a commit
to afrittoli/cdevents-spec
that referenced
this issue
Nov 25, 2023
Artifact packaged and/or published events may include a link to a published SBOM. Since there is no default storage location for such SBOM documents, CDEvents may help linking the artifact with its SBOM by including a link to the SBOM in the artifact events. Partially-addresses: cdevents#132 Signed-off-by: Andrea Frittoli <andrea.frittoli@gmail.com>
afrittoli
added a commit
to afrittoli/cdevents-spec
that referenced
this issue
Jan 12, 2024
Artifact packaged and/or published events may include a link to a published SBOM. Since there is no default storage location for such SBOM documents, CDEvents may help linking the artifact with its SBOM by including a link to the SBOM in the artifact events. Partially-addresses: cdevents#132 Signed-off-by: Andrea Frittoli <andrea.frittoli@gmail.com>
afrittoli
added a commit
that referenced
this issue
Jan 15, 2024
* Add an SBOM URI field to artifact events Artifact packaged and/or published events may include a link to a published SBOM. Since there is no default storage location for such SBOM documents, CDEvents may help linking the artifact with its SBOM by including a link to the SBOM in the artifact events. Partially-addresses: #132 Signed-off-by: Andrea Frittoli <andrea.frittoli@gmail.com>
@afrittoli , what do you see should be added from secure supply chain aspects in CDEvents that is not yet there? Should we synch up with someone in OpenSSF to sort needs out? |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Follow up for #70
We should include an SBOM field to artifact events.
The first consumer of this field will be guac.sh.
The text was updated successfully, but these errors were encountered: