You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Additionally, I'd like to propose a standardized format for referencing SBOMs within container images. Given that containers utilizes the double colon (:) in the copy command, a similar syntax could be adopted for SBOM references:
docker://<image>:<path in image> Â# Or with the tag
docker://<image>:tag:<path in image>
For example, in the case of the Juice Shop image, the SBOM could be referenced as follows:
This format provides a clear and consistent method for accessing SBOMs within container images. An alternative would be "podman://" or a container technology independentÂ"container://" which I didn't see beforehand.
The TC needs to decide
a) whether we follow the suggested format for links into containers and
b) how to provide that guidance (e.g. FAQ question, special guidance, only in a next version of the standard, etc.)
For a) we need to consider, whether and how other formats are handling these things.
The text was updated successfully, but these errors were encountered:
An alternative to URL for SBOMs is also an extra attribute, e.g. container image (e.g. bkimminich/juice-shop:v16.0.0) and an attribute path=/juice-shop/sbom.json.
Like that, CSAF will not violate RFC 3986 (I didn't check if it would violate) by using a widely adapted but not standard conform way.
While #689 (comment) would be an addition for a URL, this is an alternative to a URL.
From my point of view, this will make it easier in the software implementation in case SBOMs should be fetched automatically.
The TC received a comment via its mailing list:
The TC needs to decide
a) whether we follow the suggested format for links into containers and
b) how to provide that guidance (e.g. FAQ question, special guidance, only in a next version of the standard, etc.)
For a) we need to consider, whether and how other formats are handling these things.
The text was updated successfully, but these errors were encountered: