Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

77 add consistent creationinformation as a SBOM quality check #97

Conversation

riteshnoronha
Copy link
Contributor

SBOM generators should consistently report their name and version in the SBOM. We have noticed this is not always the case. For consumption, its essential to understand which tool was used to generate this sbom, to understand its quality.

We have added a quality score to help highlight this issue with sbom generators.

A couple of examples from the spdx ecosystem

  • Microsoft.SBOMTool-0.2.7
  • reuse-0.14.0
  • sigs.k8s.io/bom/pkg/spdx
  • apko (v0.7.1-4-ge6dcd4b)
  • trivy

@riteshnoronha riteshnoronha self-assigned this Mar 15, 2023
@riteshnoronha riteshnoronha linked an issue Mar 15, 2023 that may be closed by this pull request
surendrapathak
surendrapathak previously approved these changes Mar 15, 2023
Copy link
Collaborator

@surendrapathak surendrapathak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@riteshnoronha riteshnoronha force-pushed the 77-add-consistent-creationinformation-as-a-sbom-quality-check branch from ced0705 to f1f5713 Compare March 15, 2023 01:33
Copy link
Collaborator

@surendrapathak surendrapathak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@riteshnoronha riteshnoronha merged commit 272e6bc into main Mar 15, 2023
@surendrapathak surendrapathak deleted the 77-add-consistent-creationinformation-as-a-sbom-quality-check branch November 8, 2023 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Add consistent creationInformation as a SBOM Quality Check
2 participants