Skip to content

WIP: sbom#317

Draft
rhubert wants to merge 1 commit into
BobBuildTool:masterfrom
rhubert:sbom
Draft

WIP: sbom#317
rhubert wants to merge 1 commit into
BobBuildTool:masterfrom
rhubert:sbom

Conversation

@rhubert

@rhubert rhubert commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

Add some classes and a plugin to build a cyclonedx sbom from audit + recipe information.

Depends on: BobBuildTool/bob#700 , BobBuildTool/bob#687

Refers to: #287

Open / Todo:

  • How to handle host-dependencies (e.g. python packages) that are part of the sbom ATM since they are not tool dependences? filter-keyword for the generator?
  • How to handle License-Ref - Licenses? Should we move them up to the root package-dist? Or include them in the audit of the package already?

@jkloetzke

Copy link
Copy Markdown
Member

Thanks. 🎉 I'll hopefully have a look this week.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants