Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build info go misses checksums for many dependencies #4

Open
bbaudry opened this issue May 23, 2023 · 1 comment
Open

build info go misses checksums for many dependencies #4

bbaudry opened this issue May 23, 2023 · 1 comment

Comments

@bbaudry
Copy link

bbaudry commented May 23, 2023

I was checking the SBOM produced by build-info-go for jenkins and realized that many components are listed with no checksum
Any idea why?
https://github.com/chains-project/SBOM-2023/blob/main/results-march-2023/jenkins/build-info-go/build-info-go.json

@MartinWitt
Copy link
Contributor

Hmm, that is a good catch. Looking at the dependencies, they look like transitive dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants