-
-
Notifications
You must be signed in to change notification settings - Fork 168
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Need option to provide custom authors and metadata in the SBOM file #654
Comments
@visagansanthanam-unisys, The idea behind the default author is to show the default conditions - that the BOM was not manually edited. If your intention is to manually edit and make changes you can change the author or add to the same array. Or if you have built automation to enhance the bom then the information about the automation tool and its author can be appended in the same way so there is a history. In the future we can add multi signing and start establishing layers of trust beginning with the tool author. |
@prabhu
|
@troy256, this indeed is possible now that metadata.tools support components.author. 1.4 doesn't have support for the tool author. |
@troy256 @visagansanthanam-unisys could you kindly test the PR branch #660 and let me know how it looks? |
@prabhu Using the
|
@troy256, authors can be passed via environment variables and config files, too. |
in current scenario when a SBOM is generated, it has the author information as part of the metadata.
The default authors details can be part of the tools section itself as shown below, since the author mentioned is the author of the tool used and not the SBOM itself
and there should be option to provide key value pair based custom meta data which can used to add the details like the Author or product owner or release data etc..
The text was updated successfully, but these errors were encountered: