Create a CycloneDX SBOM for the full reproducible build_info #2785
Labels
enhancement
Issues that enhance the code or documentation of the repo in any way
reproducible-build
Sbom
issue relate to work of sbom
security
Issue: #2753
investigates the required extended dependencies that determine a given build binary output.
This issue is to take that research and create a new CycloneDX SBOM for that full "build info".
The intended use case this should then satsify is:
"Given a full CycloneDX SBOM for an Adoptium reproducible binary, a 3rd party will be able to setup those required dependencies and build a reproducible identical binary"
The text was updated successfully, but these errors were encountered: