DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
WH Theme: SBOMS / Notifications
- Look at OpenSSF SLSA/SBOM work (SLSA). See also mail from GOSST
- Look at https://github.com/ossf/wg-security-tooling
- https://github.com/spdx/spdx-maven-plugin
Draft ASF Position:
- SBOMs needs to be automatically generated for builds at build time
- SBOMs need to be signed with the same keys used for releases
- SBOMs are expected to be static, never changed after release
- SBOMs need to be useful (i.e. can be parsed, machine readable by current/future tools)
Questions
- What type of projects/builds should include SBOMs?
- What format should be used (e.g., SPDX, CycloneDX)
- What projects are interested in working on this?