Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs: write a how to guide for SBOM scanning #2922

Closed
terriko opened this issue Apr 19, 2023 · 1 comment
Closed

docs: write a how to guide for SBOM scanning #2922

terriko opened this issue Apr 19, 2023 · 1 comment
Assignees
Labels
documentation Documentation changes hackathon Issues for folk participating in the OSS hackathon

Comments

@terriko
Copy link
Contributor

terriko commented Apr 19, 2023

Right now, we've got a whole lot of SBOM related options in the cve-bin-tool manual and some sorter getting started stuff in the Readme, but it would be really nice to have a whole guide dedicated to SBOM scanning.

Some thoughts about what to include:

  • How to use the various options with examples
  • What to expect / not expect from an SBOM scan
  • How to improve lookups: e.g. currently we're searching for case insensitive exact names, so if your sbom has a weird name or prefixes the product name somehow it may not work. (See also bug: libraries ignored by cve-bin-tool ? #2846 for a recent case of it not working as expected)
  • recommendation of tools for generating sboms?

Also, if you're in to videos a lot of people ask for those as part of our documentation but we currently don't provide them other than our conference talks, so this might be an option too.

This issue is reserved for a participant in the Open Source Hackaton 2023. Please leave it for hackathon participants through the end of April. If it hasn't been claimed by May 5 it will be open to any contributor who wants to work on it.

@terriko terriko added documentation Documentation changes hackathon Issues for folk participating in the OSS hackathon labels Apr 19, 2023
@offsake
Copy link
Contributor

offsake commented Apr 25, 2023

Hackathon Team 2 is working on this issue.

fmbertol added a commit to offsake/cve-bin-tool that referenced this issue Apr 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Documentation changes hackathon Issues for folk participating in the OSS hackathon
Projects
None yet
Development

No branches or pull requests

2 participants