Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Include language package manager (e.g. cargo, npm, go modules) information in SBOMs #17423

Open
1 task done
carlocab opened this issue Jun 4, 2024 · 2 comments
Open
1 task done
Labels
features New features help wanted We want help addressing this

Comments

@carlocab
Copy link
Member

carlocab commented Jun 4, 2024

Verification

Provide a detailed description of the proposed feature

The sbom.spdx.json contains dependency information for dependencies managed by brew. We should include dependency information for those not managed by brew as well.

What is the motivation for the feature?

More complete SBOMs. It will also improve our ability to track CVEs that affect formulae.

How will the feature be relevant to at least 90% of Homebrew users?

It probably won't be.

What alternatives to the feature have been considered?

  • the status quo
  • another mechanism for tracking non-Homebrew dependencies
@carlocab carlocab added the features New features label Jun 4, 2024
@MikeMcQuaid
Copy link
Member

Good idea, thanks @carlocab!

@MikeMcQuaid MikeMcQuaid added the help wanted We want help addressing this label Jun 4, 2024
@SMillerDev
Copy link
Member

@carlocab do you have an example of some data you would like to see included?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
features New features help wanted We want help addressing this
Projects
None yet
Development

No branches or pull requests

3 participants