Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a CycloneDX SBOM for the full reproducible build_info #2785

Closed
andrew-m-leonard opened this issue Nov 4, 2021 · 2 comments
Closed
Labels
enhancement Issues that enhance the code or documentation of the repo in any way reproducible-build Sbom issue relate to work of sbom security

Comments

@andrew-m-leonard
Copy link
Contributor

Issue: #2753
investigates the required extended dependencies that determine a given build binary output.
This issue is to take that research and create a new CycloneDX SBOM for that full "build info".

The intended use case this should then satsify is:
"Given a full CycloneDX SBOM for an Adoptium reproducible binary, a 3rd party will be able to setup those required dependencies and build a reproducible identical binary"

@andrew-m-leonard andrew-m-leonard added reproducible-build enhancement Issues that enhance the code or documentation of the repo in any way labels Nov 4, 2021
@zdtsw
Copy link
Contributor

zdtsw commented Jul 8, 2022

i think this issue should be closed?
we can discuss more detail what need to be in sbom in #3013

@zdtsw zdtsw added the Sbom issue relate to work of sbom label Jul 8, 2022
@andrew-m-leonard
Copy link
Contributor Author

Yes we can discuss in #3013

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Issues that enhance the code or documentation of the repo in any way reproducible-build Sbom issue relate to work of sbom security
Projects
No open projects
Development

No branches or pull requests

3 participants