-
Notifications
You must be signed in to change notification settings - Fork 62
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Pick an SBOM format #3
Comments
Related: here's CycloneDX's (official?) Python module: https://github.com/CycloneDX/cyclonedx-python |
There's also https://github.com/CycloneDX/cyclonedx-python-lib which is a reusable library containing the model and serializations to JSON and XML. https://github.com/CycloneDX/cyclonedx-python builds on top of the python library. Let us know if you have any questions implementing CycloneDX. There's a vibrant community of adopters and implementors in the project Slack workspace. And yes, they are both officially supported implementations. |
Thanks for linking those! |
Based on the current maturity of the Python SPDX ecosystem, I'm inclined to say that we should go with CycloneDX for now. We'll probably want to use Some braindump notes:
Closing so that we can formally unblock #77. |
Emitting a well-known SBOM format is a lower priority, but it's something we specified in the proposal.
Two good options are SPDX and CycloneDX; we should determine:
The text was updated successfully, but these errors were encountered: