Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Pre-build" life cycle phase additions about Open Source supply-chain & ecosystem #18

Open
sjn opened this issue Feb 19, 2024 · 1 comment

Comments

@sjn
Copy link

sjn commented Feb 19, 2024

I'm wondering it would be very beneficial to expand the "pre-build" phase in 0x20-Lifecycle_Phases.md.

I imagine this phase implies quite a few important steps involved in the final assembly of an SBOM, including authoritative information about components acquired from a supplier up-stream, that may be

  • updated unilaterally by the component author.
    • Author name
    • Author email
    • Component unique name
    • Component version/release
    • Project name
    • Project repository
    • Project contact information
    • Project license
    • Project issue/bug tracker URL
    • List of know vulnerabilities this release has addressed
    • etc..
  • updated unilaterally by the software distribution service (e.g. a native package source, like Debian's APT repositories, or FreeBSD's ports system)
    • Package download URL
    • Packager's name
    • Packager's email
    • Packager's security advisory URL
    • List of patches/changes applied by the packager
    • etc…
@stevespringett
Copy link
Member

Thanks @sjn. However, I don't know what the ask is. Can you expand on what you'd like to see and what would be beneficial to readers?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants