Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add command that produces an SBOM for an existing image #1284

Open
luhring opened this issue Aug 23, 2024 · 0 comments
Open

Add command that produces an SBOM for an existing image #1284

luhring opened this issue Aug 23, 2024 · 0 comments

Comments

@luhring
Copy link
Contributor

luhring commented Aug 23, 2024

Today apko has an approach to producing SBOMs for images it builds: it aggregates the SBOM information from the list of APK packages used in the image into a single image SBOM.

But it doesn't let the user just produce the SBOM for an image (using that same approach).

This would be useful in debugging issues with existing images and their SBOMs, such as to verify that an image's existing SBOM has been produced and/or updated correctly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant