-
Notifications
You must be signed in to change notification settings - Fork 175
Open
Labels
area:nodejsIssue related to the Node.js builderIssue related to the Node.js buildertype:featureNew feature or requestNew feature or request
Description
This could be enabled thru a sbom-generate: true and sbom-format: xxx options. I think a scan of the package.json would work, although I'm not 100% sure if additional deps could be pulled in thru the script...
A larger question we need to answer before doing that is how we attest to the SBOM: thru a dedicated provenance, thru a new predicateType, thru byproduct of the existing provenance.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area:nodejsIssue related to the Node.js builderIssue related to the Node.js buildertype:featureNew feature or requestNew feature or request