You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Record the hashes of the generated binaries, so that a SBOM can be reliably matched to a given binary
Record the hashes of the source-level .crate files downloaded from package registries, to unambiguously attribute them to a specific registry version
The first one depends on #532, but the second can be implemented by parsing Cargo.lock now that cargo metadata has stabilized package identifiers as cargo pkgid format, so it is now possible to cross-reference cargo metadata output with Cargo.lock.
No description provided.
The text was updated successfully, but these errors were encountered: