Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate and commit SBOMs for our components #2339

Draft
wants to merge 1 commit into
base: main
Choose a base branch
from
Draft

Generate and commit SBOMs for our components #2339

wants to merge 1 commit into from

Conversation

legoktm
Copy link
Member

@legoktm legoktm commented Dec 17, 2024

Status

Work in progress

Description

These focus on the Python and Rust dependencies, without touching the myriad Debian and other dependencies we pull in at build time.

This builds the foundation for us to start adding more stuff.

Refs freedomofpress/securedrop-tooling#15.

TODO

  • CI integration
  • CycloneDX vs SPDX
  • What's the actual value of generating SBOMs right now? Will we centralize security monitoring around this?

Test Plan

TK

These focus on the Python and Rust dependencies, without touching the
myriad Debian and other dependencies we pull in at build time.

This builds the foundation for us to start adding more stuff.

Refs <freedomofpress/securedrop-tooling#15>.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant