Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Frontend SBOM to Support CycloneDX 1.5 or 1.6 #911

Open
2 tasks done
msymons opened this issue Jun 19, 2024 · 3 comments
Open
2 tasks done

Update Frontend SBOM to Support CycloneDX 1.5 or 1.6 #911

msymons opened this issue Jun 19, 2024 · 3 comments
Labels
enhancement New feature or request size/S Small effort
Milestone

Comments

@msymons
Copy link
Member

msymons commented Jun 19, 2024

Current Behavior

The latest release of DT Frontend is v4.11.3 and the BOM is published as a release asset and also available from DT itself via /.well-known/sbom

The BOM is generated using CycloneDX Webpack Plugin v2.0.2 which only supports CDX 1.3.

Proposed Behavior

  • Upgrade plugin from 2.0.2 to 3.12.0 (or later)
  • Ensure that specVersion = 1.5 or 1.6. The latest version of the webpack-plugin does support CDX 1.6

Checklist

@msymons msymons added the enhancement New feature or request label Jun 19, 2024
@msymons msymons added this to the 4.12 milestone Jun 19, 2024
@msymons msymons changed the title Update Frontend to Support CycloneDX 1.5 or 1.6 Update Frontend SBOM to Support CycloneDX 1.5 or 1.6 Jun 19, 2024
@nscuro
Copy link
Member

nscuro commented Jun 19, 2024

There is a Dependabot PR to bump the plugin version, but the build is failing: #912

Needs investigation. Perhaps we can't go directly to the latest plugin version due to other dependencies we need to upgrade first...

@nscuro nscuro added the size/S Small effort label Jun 19, 2024
@Gepardgame
Copy link
Contributor

That's the state on this PR? It has the 4.12 milestone, but had no activity for a while

@nscuro
Copy link
Member

nscuro commented Sep 30, 2024

Will require a Webpack upgrade, which is bound to a Vue upgrade. Postponing.

@nscuro nscuro modified the milestones: 4.12, 4.13 Sep 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request size/S Small effort
Projects
None yet
Development

No branches or pull requests

3 participants