Skip to content

Commit

Permalink
Add a SBOM template in CycloneDX format (#585)
Browse files Browse the repository at this point in the history
Improve supply chain security by including a SBOM file with substituted values.

This will be used to construct a composite platform SBOM.

Signed-off-by: Richard Hughes <richard@hughsie.com>
  • Loading branch information
hughsie authored Dec 12, 2024
1 parent dfa44a9 commit 7e1ee0f
Showing 1 changed file with 45 additions and 0 deletions.
45 changes: 45 additions & 0 deletions sbom.cdx.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"version": 1,
"metadata": {
"authors": [
{
"name": "@VCS_SBOM_AUTHORS@"
}
]
},
"components": [
{
"type": "library",
"bom-ref": "pkg:github/open-quantum-safe/oqs-provider@@VCS_TAG@",
"name": "oqsprovider",
"version": "@VCS_VERSION@",
"description": "Research and prototyping OSSL provider for post quantum cryptographic algorithms (NOT RECOMMENDED FOR PRODUCTION USE)",
"authors": [
{
"name": "@VCS_AUTHORS@"
}
],
"supplier": {
"name": "The OQS core team"
},
"licenses": [
{
"license": {
"id": "MIT"
}
}
],
"externalReferences": [
{
"type": "vcs",
"url": "https://github.com/open-quantum-safe/oqs-provider"
}
],
"pedigree": {
"notes": "DO NOT TRUST"
}
}
]
}

0 comments on commit 7e1ee0f

Please sign in to comment.