Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SBOM Naming - SBOMs required for all ecosystems? #44

Open
idunbarh opened this issue Feb 27, 2024 · 2 comments
Open

SBOM Naming - SBOMs required for all ecosystems? #44

idunbarh opened this issue Feb 27, 2024 · 2 comments

Comments

@idunbarh
Copy link
Contributor

Question that came up around adding SBOM checks to Scorecard.

How do we determine if the project should create an SBOM or not, depending on the type of release (application, library, ?) - see https://blog.deps.dev/zillions-of-sboms/. Is there a document describing when an SBOM makes sense in each ecosystem?

While this might lead to a larger discussion, I think its a question that will repeatedly come up.

@idunbarh
Copy link
Contributor Author

Thoughts @joshbressers if there is value in this being a future SBOM Everywhere SIG discussion topic?

@joshbressers
Copy link
Contributor

I totally missed this, apologies (it's been a wild couple of weeks).

We did discuss this a bit today in our call. I think fundamentally this is a question that needs to be answered as part of the strike team effort

https://docs.google.com/document/d/15_FKO8D03VSYDTNsMQZtn1aRfgVmModF-NM6VBnlrZA/edit#heading=h.1jccoh7pyeo0

I don't think they are necessarily tied together, as this could be written at anytime. Anyone is welcome to start drafting this document (put it in the reference folder, or a google doc is fine)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants