Skip to content

[feature][npm] Generate SBOM for npm #1982

@laurentsimon

Description

@laurentsimon

This could be enabled thru a sbom-generate: true and sbom-format: xxx options. I think a scan of the package.json would work, although I'm not 100% sure if additional deps could be pulled in thru the script...

A larger question we need to answer before doing that is how we attest to the SBOM: thru a dedicated provenance, thru a new predicateType, thru byproduct of the existing provenance.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:nodejsIssue related to the Node.js buildertype:featureNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions