-
-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
📣 looking for contributors #12
Comments
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
(Just in case it helps : yarnpkg/berry#6063) |
@jkowalleck I've experimented yesterday with creating a Yarn plugin to generate CycloneDX SBoMs. The generated files look good at first glance. Note however that I don't want to make any promises just yet without doing some further assessments if the taken approach is sound. Expect some update on this in a couple of days. |
@jkowalleck, @sbernard31 see draft in PR #13. This plugin generates correctly looking SBOMs for the projects I've tested with as far as I can judge. Easiest way to test on existing Yarn projects is The more sensible way is:
|
Implementation is coming to an end, nearly all features are done. |
CycloneDX is a community effort, free for all.
Based on #8
This project is currently looking for contributors/champions.
Drop a note, or ping, if you are interested.
The text was updated successfully, but these errors were encountered: