Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update or change tool used to generate sboms #1235

Open
banjoh opened this issue Jun 20, 2023 · 2 comments
Open

Update or change tool used to generate sboms #1235

banjoh opened this issue Jun 20, 2023 · 2 comments

Comments

@banjoh
Copy link
Member

banjoh commented Jun 20, 2023

Describe the rationale for the suggested feature.

Troubleshoot uses spdx-sbom-generator whose latest release is https://github.com/opensbom-generator/spdx-sbom-generator/releases/tag/v0.0.15, released a year ago (July 12th). It has some dependencies that have CVEs that need to be updated. The project is active but no newer releases made yet. There is a pending issue

Describe the feature

Review usage of spdx-sbom-generator. There are quite a number of tools out there such as https://github.com/microsoft/sbom-tool, https://github.com/kubernetes-sigs/bom and a few others I have not listed.

@xavpaice
Copy link
Member

@banjoh is this still the case?

@banjoh
Copy link
Member Author

banjoh commented Nov 20, 2024

It's still the case. The last release was made in 2022.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants