Skip to content

[cli] container image-based generator #1699

@prabhu

Description

@prabhu

The upcoming version of depscan v6 introduces the concept of BOM engines, with CdxgenImageBasedGenerator being one of them.

https://github.com/owasp-dep-scan/dep-scan/blob/117d85be50c7df4c5059a5eddc284f7e918b69a2/packages/xbom-lib/src/xbom_lib/cdxgen.py#L250

It would be great to port this feature to cdxgen v12 and enhance the current CLI to first detect project types, then generate BOMs using the appropriate container images before performing aggregation. This would improve the precision a bit at the cost of increased gen time (which is fine).

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions