Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Creating SBOM #17622

Open
OrlinVasilev opened this issue Oct 3, 2022 · 4 comments
Open

Creating SBOM #17622

OrlinVasilev opened this issue Oct 3, 2022 · 4 comments
Assignees
Labels
kind/requirement New feature or idea on top of harbor

Comments

@OrlinVasilev
Copy link
Member

Hi team,
we need a way to create SBOM for Harbor and have it statically created or to attach it with each release

Here is why: https://clomonitor.io/docs/topics/checks/#software-bill-of-materials-sbom
we need to be compliant on 100%

I think we can use something like the Kubernetes BOM tool: https://github.com/kubernetes-sigs/bom
or something else!

Orlix

@OrlinVasilev OrlinVasilev self-assigned this Oct 3, 2022
@ChristianCiach
Copy link

ChristianCiach commented Oct 4, 2022

Seeing that there are ideas to leverage the Cosign specification to attach SBOM images, maybe this would be a nice case of dogfooding:

@wy65701436 wy65701436 added the kind/requirement New feature or idea on top of harbor label Oct 10, 2022
@F-Baker
Copy link

F-Baker commented Jul 6, 2023

Hello, I'd like to help with this. Where can I start?
Thanks

@OrlinVasilev
Copy link
Member Author

@wy65701436 we have to close this when we have 2.10 out :)

@Vivekgaddigi
Copy link

2,10 is out is this still relevant?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/requirement New feature or idea on top of harbor
Projects
None yet
Development

No branches or pull requests

6 participants