-
Notifications
You must be signed in to change notification settings - Fork 17
Check how to use SBOM #95
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
A good reference to explain how it is done with Yocto: https://summit.yoctoproject.org/yocto-project-summit-2022-11/talk/NAENTD/ |
I'm not sure I understand "Debian FAI does not support SBOM" |
I think that this could be more complicated. The first question is to list what should be required. ● Sources Again we would need to discuss that. |
Some LFEnergy discussions in 2021 regarding this topic: https://docs.google.com/presentation/d/1iSLCinJoZ_TsUjogeyTr-ypmyASho5R6YOCNzZSmEIk/edit#slide=id.gb62873e1e9_1_53 |
SBoM information is essential for vulnerability and license
compliance assessment
The US government is pushing for having such information
in all software it procures and will probably make it mandatory soon.
Debian FAI does not support SBOM.
The text was updated successfully, but these errors were encountered: