-
Notifications
You must be signed in to change notification settings - Fork 19
docs: ADR-0007 sbom diff #112
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: Michal Frystacky <michal.frystacky@lmco.com>
|
@houdini91, I think @puerco mentioned that you are working on a |
Signed-off-by: Michal Frystacky <michal.frystacky@lmco.com>
Signed-off-by: Michal Frystacky <michal.frystacky@lmco.com>
|
Mind updating the PR description like the others with the content of the ADR document? |
|
Done! |
I meant copy the content of the new ADR document, edit the PR description, and replace everything with paste |
Signed-off-by: Michal Frystacky <michal.frystacky@lmco.com>
|
Capturing the thoughts that I brought up in the working meeting:
|
7. SBOM Diff
Date: 2024-07-30
Status
Proposed
Context
Support the ability to see the difference between two SBOMs.
Decision
Seeing where two SBOMs differ and highlighting potentially problematic changes such as:
Some tools do that do that on the package lock level since that sort of supply chain attack is starting to get a bit more prevalent.
Are there other useful things we should highlight for the user?
Consequences