Open Supplychain Information Modeling TC

 View Only

Defining what is in an SBOM vs what to call "SBOM-plus"

  • 1.  Defining what is in an SBOM vs what to call "SBOM-plus"

    Posted 06-28-2024 15:07

    I have created issues #28, #29, #30, and #31 which sort of go together. A root issue we will need to solve is dealing with "ancillary" information like licensing, vulnerabilities, EoX, provenance, pedigree, etc. I propose to kick off that discussion as part of defining terms. Thoughts, discussions, disagreements welcome. Please add to the discussion on the issues in GitHub – even if it's just to agree.

     

    -- 

    Duncan Sparrell

    sFractal Consulting

    iPhone, iTypo, iApologize

    I welcome VSRE emails. Learn more at http://vsre.info/