Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No Supplier for each component within SBOM #2993

Closed
merlin-uk opened this issue Jun 25, 2024 · 2 comments
Closed

No Supplier for each component within SBOM #2993

merlin-uk opened this issue Jun 25, 2024 · 2 comments
Labels
enhancement New feature or request

Comments

@merlin-uk
Copy link

What would you like to be added:
Please add "Supplier" to each component.
Why is this needed:
The Supplier is needed to make SBOM valid.
Additional context:

@merlin-uk merlin-uk added the enhancement New feature or request label Jun 25, 2024
@kzantow
Copy link
Contributor

kzantow commented Jun 25, 2024

The Supplier is needed to make SBOM valid.

This is not required to make a valid SBOM. It is required for NTIA minimum elements.

The challenge we have here is that we simply don't have supplier information present in the scan target for everything. However, we are including supplier, in many cases if we found this information.

Is there something else you are looking for? Could you provide more information: what package ecosystem, what output format, sample images you expect to have suppliers, etc.?

@kzantow
Copy link
Contributor

kzantow commented Jul 3, 2024

I'm going to close this issue, as I believe it's a duplicate of #1961. If that's not correct, please let me know! And if you have some examples to provide to help us make sure we're surfacing supplier information for ecosystems, please do let us know that as well.

@kzantow kzantow closed this as not planned Won't fix, can't repro, duplicate, stale Jul 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Archived in project
Development

No branches or pull requests

3 participants