Skip to content

Conversation

@dervoeti
Copy link
Member

@dervoeti dervoeti commented Sep 6, 2024

Last thing needed for stackabletech/issues#614

Changes:

  • Update Syft to latest version
  • Fix CycloneDX version to 1.5
  • Enable Syft's sbom-cataloger to pick up the build-time generated SBOMs
  • Use https://github.com/stackabletech/mergebom to merge the information found in the new SBOMs inside the images with the information found by Syft's other catalogers. More details about this can be found in Nuclino and in the comments of mergebom.

@dervoeti dervoeti requested a review from lfrancke September 9, 2024 12:45
@dervoeti dervoeti requested a review from lfrancke September 9, 2024 12:58
@dervoeti dervoeti added this pull request to the merge queue Sep 9, 2024
Merged via the queue into main with commit ba3d42b Sep 9, 2024
1 check passed
@dervoeti dervoeti deleted the feat/merge-sbom-components branch September 9, 2024 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants