Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate CycloneDX BOM #8251

Closed
mterron opened this issue Jul 30, 2019 · 5 comments
Closed

Generate CycloneDX BOM #8251

mterron opened this issue Jul 30, 2019 · 5 comments

Comments

@mterron
Copy link

mterron commented Jul 30, 2019

Can you add a feature to generate a CycloneDX compatible BOM to composer?

Here's the spec: https://cyclonedx.org/docs/1.1/

All the information is already in composer so shouldn't be too hard.

@Seldaek
Copy link
Member

Seldaek commented Jul 30, 2019

I have no idea what you are talking about, nor what cyclonedx is, nor why I should spend time figuring out any of this.. So unless you spend some effort at least explaining I'd say no :)

@mterron
Copy link
Author

mterron commented Jul 30, 2019

CycloneDX is the std format for software composition management software to consume.

See OWASP DependencyTrack as an example.

To get PHP supported by DependencyTrack a way to generate a compliant BOM is needed.

@mterron mterron closed this as completed Jul 30, 2019
@Seldaek
Copy link
Member

Seldaek commented Jul 30, 2019

Ok.. we can keep this open as a way to track it, but tbh this isn't gonna be high on the priority list at the moment.

@Seldaek Seldaek reopened this Jul 30, 2019
@Seldaek Seldaek added this to the Nice To Have milestone Jul 30, 2019
@jakoch
Copy link
Contributor

jakoch commented Oct 26, 2020

There is a plugin for this feature request: https://github.com/CycloneDX/cyclonedx-php-composer

@Seldaek
Copy link
Member

Seldaek commented Oct 26, 2020

Ah very nice, closing this then. Definitely better handled as a third party package as I don't think we want to maintain this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants