Skip to content

Conversation

@j-hartley
Copy link

Problem:

The BOM generated by syft does not contain all the recommended minimum
data for SBOM best practice, see:
https://www.ntia.doc.gov/report/2021/minimum-elements-software-bill-materials-sbom

Solution:

Patch the missing elements into the SBOM prior to uploading.
Validate the SBOM against the cyclone DX 1.2 XML schema to make sure it
is correctly constructed.

@j-hartley j-hartley force-pushed the dev/j-hartly/add-ntia-minimum-elements branch from 2332d54 to 18954cf Compare November 29, 2021 09:41
Problem:

The BOM generated by syft does not contain all the recommended minimum
data for SBOM best practice, see:
https://www.ntia.doc.gov/report/2021/minimum-elements-software-bill-materials-sbom

Solution:

Patch the missing elements into the SBOM prior to uploading.
Validate the SBOM against the cyclone DX 1.2 XML schema to make sure it
is correctly constructed.

Signed-off-by: John Hartley
@j-hartley j-hartley force-pushed the dev/j-hartly/add-ntia-minimum-elements branch from 18954cf to 94f3618 Compare November 29, 2021 09:43
@j-hartley j-hartley merged commit 6dd4a86 into main Nov 29, 2021
@j-hartley j-hartley deleted the dev/j-hartly/add-ntia-minimum-elements branch November 29, 2021 09:54
@j-hartley j-hartley restored the dev/j-hartly/add-ntia-minimum-elements branch November 29, 2021 10:47
@j-hartley j-hartley deleted the dev/j-hartly/add-ntia-minimum-elements branch November 29, 2021 14:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants