Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Produce a SBOM using fossa or another acceptable tool #818

Open
ryanfaircloth opened this issue Jan 16, 2024 · 6 comments
Open

Produce a SBOM using fossa or another acceptable tool #818

ryanfaircloth opened this issue Jan 16, 2024 · 6 comments
Assignees

Comments

@ryanfaircloth
Copy link
Contributor

While discussing a PR a concern was raised about license compliance this seems to be a reasonable concern and the appropriate resolution is producing a automated bill of materials

@satoru-takeuchi
Copy link
Member

memo:

While discussing a PR

#816

@satoru-takeuchi satoru-takeuchi self-assigned this Jan 17, 2024
@satoru-takeuchi
Copy link
Member

It's reasonable. I'll use a tools to avoid licence compliance problem. I'll use FOSSA as Ryan said. @jakobmoellerdev Do you have any recommendation? I believe Red Hat has plenty of know-how.

@jakobmoellerdev
Copy link
Contributor

I'll ask in our OSS / Compliance department if there is anything specific we want there. Will get back here once I have an update.

@jakobmoellerdev
Copy link
Contributor

I asked around and got recommended https://github.com/anchore/syft which can be used for SBOM generation that will also be able to be attached to releases via automation. It should also be able to cover Licensing if I understood them correctly but didnt verify this closely.

@satoru-takeuchi
Copy link
Member

Thank you. I found syft provides licence check by calling bouncer.

https://github.com/anchore/syft/blob/11c0b1c234c461825d4897273e26e37c8c5e26d5/Taskfile.yaml#L157

I'll check this tool in detail and will compare with other tools.

Copy link
Contributor

This issue has been automatically marked as stale because it has not had any activity for 30 days. It will be closed in a week if no further activity occurs. Thank you for your contributions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Waiting
Development

No branches or pull requests

4 participants