Adam Kaplan
He/Him
Senior Principal Software Engineer
100 E. Davie Street
I am not aware of any non-container package ecosystem that has a standard mechanism for distributing SBOMs (I'd love to be proved wrong here).
--
You received this message because you are subscribed to the Google Groups "Konflux CI" group.
To unsubscribe from this group and stop receiving emails from it, send an email to konflux+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/konflux/CADmLb%2BmKezbDTLTeftpUrb8PaXrx-BSzjTWcNy1eyo9j_5kqTA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
Because making adjustments would require that we re-inject the SBOM into the built artifact, which would change its digest, which would break the provenance
Do we include SBOMs in container images today?
For software artifacts that aren't containers, there is no digest to compare against when we publish content.
subject[0].name is the distribution’s filename, which MUST be
a valid source distribution or
wheel distribution filename.subject[0].digest MUST contain a SHA-256 digest. Other digests
MAY be present. The digests MUST be represented as hexadecimal strings.To view this discussion visit https://groups.google.com/d/msgid/konflux/CADmLb%2B%3D_h%2BCrcx09NLhbbHW9SfEPeq-%3DLq3t57pt2gG4ZzEwpQ%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/konflux/CADmLb%2Bm71zKTg6B7WKkBd2_4bos9DyGMHdErBnnGJYHDxe5Zyg%40mail.gmail.com.