Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support of build-time generation #27

Open
ivanayov opened this issue Sep 20, 2022 · 0 comments
Open

Support of build-time generation #27

ivanayov opened this issue Sep 20, 2022 · 0 comments
Labels
enhancement New feature or request

Comments

@ivanayov
Copy link

Hello,

What would you like to be added:

Have you thought about adding build time support?

Why is this needed:

With post-build scanning it's still possible to miss some detail, like changes done by the compiler or other tools used during building an image.

Only few sbom generation tools already support build-time generation (like Salus or pkgconf bomtool for example), but non of them is universal and complete to capture various docker builds.

The only option for the moment is implementing a build-time sbom generation tool that fits for building docker images and making it part of the build process, which is a fully valid and well-working option. Still, as there is already an experimental docker sbom feature, it would be great to have generic build time configuration.

@ivanayov ivanayov added the enhancement New feature or request label Sep 20, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant