Skip to content

Conversation

@eccles
Copy link
Contributor

@eccles eccles commented Dec 8, 2021

Problem:
SBOMS from jar files xmllint checks.

Solution:
Add optional -P flag to suppress validation and allow
either versiosn aor hashes.

Signed-off-by: Paul Hewlett phewlett76@gmail.com

@eccles eccles force-pushed the dev/eccles/sbomscraper-jar-files branch from f5d1e0c to adc4c9f Compare December 8, 2021 15:50
@eccles eccles force-pushed the dev/eccles/sbomscraper-jar-files branch 2 times, most recently from 1291f31 to 1c6a112 Compare December 8, 2021 16:23
@eccles eccles changed the title Upload SBOM from jar filee Upload SBOM from jar file Dec 8, 2021
@eccles eccles force-pushed the dev/eccles/sbomscraper-jar-files branch 5 times, most recently from fff564f to d787a93 Compare December 9, 2021 14:11
@eccles eccles requested a review from landintrees December 9, 2021 17:30
@eccles eccles force-pushed the dev/eccles/sbomscraper-jar-files branch 2 times, most recently from d7edeec to 0620243 Compare December 14, 2021 14:17
Copy link

@landintrees landintrees left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Look good, thanks

Problem:
Deriving SBOMS from jar files requires extra steps and
extra consolidation of internal fields.

Solution:
If a jar URL then fetch and execute syft with 'file:' qualifier.
Add conditional mods to fields in generated sbom to comply with
NTIA requirements.

Signed-off-by: Paul Hewlett <phewlett76@gmail.com>
@eccles eccles force-pushed the dev/eccles/sbomscraper-jar-files branch from eaf945c to 1a50db7 Compare December 16, 2021 10:36
@eccles eccles merged commit 4ecb604 into main Dec 16, 2021
@eccles eccles deleted the dev/eccles/sbomscraper-jar-files branch December 16, 2021 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants