Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Try out SBOMs/SLSA/Scorecard documents from more sources #193

Open
lumjjb opened this issue Oct 25, 2022 · 2 comments
Open

Try out SBOMs/SLSA/Scorecard documents from more sources #193

lumjjb opened this issue Oct 25, 2022 · 2 comments
Labels
good first issue Good for newcomers help wanted Extra attention is needed

Comments

@lumjjb
Copy link
Contributor

lumjjb commented Oct 25, 2022

We've currently only tried our parser on outputs from Syft and SLSA of the k8s community. We encourage folks to try out new sources and different documents, the findings can be reported at #169 - also let us know which ones work well!

@lumjjb lumjjb added good first issue Good for newcomers help wanted Extra attention is needed labels Oct 25, 2022
@tixu
Copy link

tixu commented Oct 31, 2022

Is there a template to respond to this issue? I have tried sbom (format cyclonedx) into the tool it upload the nodes but not the root package and there is no associations. Do you want to limit your tool to OCI images & container? I think there is a lot of added value to have various language/ tools supported.

@pxp928
Copy link
Collaborator

pxp928 commented Oct 31, 2022

Hey @tixu. Issue #169 does have a format defied that you can follow if you are having issues with the specific SBOM. #184 is related as we are currently using heuristics to parse the root package (in the case of an image). We will be increasing support for more artifacts in the near future.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

3 participants