|
Re: GitHub blogged they are creating SBOMs in SPDX format
Hi,
Try Export SBOM at:
https://github.com/nexB/license-expression/network/dependencies
Best regards,
Marc-Etienne
Hi,
Try Export SBOM at:
https://github.com/nexB/license-expression/network/dependencies
Best regards,
Marc-Etienne
|
By
Vargenau, Marc-Etienne (Nokia - FR/Paris-Saclay)
·
#1655
·
|
|
Re: GitHub blogged they are creating SBOMs in SPDX format
We raised the first issue with them yesterday and they are working on it. Do you have more detail on the second?
Get Outlook for iOS
We raised the first issue with them yesterday and they are working on it. Do you have more detail on the second?
Get Outlook for iOS
|
By
William Bartholomew (CELA)
·
#1654
·
|
|
Re: GitHub blogged they are creating SBOMs in SPDX format
Hi,
I did some quick tests.
I always get invalid SPDX, mostly with “Empty license expression” and “No SPDX element found for SPDX ID” flagged by the validator.
Does anyone know where
Hi,
I did some quick tests.
I always get invalid SPDX, mostly with “Empty license expression” and “No SPDX element found for SPDX ID” flagged by the validator.
Does anyone know where
|
By
Vargenau, Marc-Etienne (Nokia - FR/Paris-Saclay)
·
#1653
·
|
|
Re: SPDXMerge Tool
#spdx
This is awesome thank you Sandeep!
Joseph D. Silvia
Director Software Quality Training and Consulting
Oriel STAT A MATRIX|Improving Workplace Performance Since 1968
1055 Thomas Jefferson St. NW,
This is awesome thank you Sandeep!
Joseph D. Silvia
Director Software Quality Training and Consulting
Oriel STAT A MATRIX|Improving Workplace Performance Since 1968
1055 Thomas Jefferson St. NW,
|
By
Joseph Silvia
·
#1652
·
|
|
Re: SPDXMerge Tool
#spdx
Thanks Sandeep,
Excellent contribution to the community!
Gary
Thanks Sandeep,
Excellent contribution to the community!
Gary
|
By
Gary O'Neall
·
#1651
·
|
|
GitHub blogged they are creating SBOMs in SPDX format
Looks like GitHub has a self-service option to create SBOMs for a GitHub Project based on SPDX!
See this blog from them.
Best Regards,
Jack Manbeck
Outreach Chair
Looks like GitHub has a self-service option to create SBOMs for a GitHub Project based on SPDX!
See this blog from them.
Best Regards,
Jack Manbeck
Outreach Chair
|
By
Manbeck, Jack
·
#1650
·
|
|
Re: SPDXMerge Tool
#spdx
Thanks Sandeep,
Excellent contribution to the community!
Gary
Thanks Sandeep,
Excellent contribution to the community!
Gary
|
By
Gary O'Neall
·
#1649
·
|
|
Re: SPDXMerge Tool
#spdx
Thanks Sandeep,
Excellent contribution to the community!
Gary
Thanks Sandeep,
Excellent contribution to the community!
Gary
|
By
Gary O'Neall
·
#1648
·
|
|
Re: SPDXMerge Tool
#spdx
Thanks Sandeep,
Excellent contribution to the community!
Gary
Thanks Sandeep,
Excellent contribution to the community!
Gary
|
By
Gary O'Neall
·
#1647
·
|
|
Re: SPDXMerge Tool
#spdx
Thanks Sandeep,
Excellent contribution to the community!
Gary
Thanks Sandeep,
Excellent contribution to the community!
Gary
|
By
Gary O'Neall
·
#1646
·
|
|
Re: SPDXMerge Tool
#spdx
Hi Sandeep,
Very cool! FYI, This is very similar to a tool Ivana and I recently developed and donated to the opensbom org:https://github.com/opensbom-generator/sbom-composer😊
-Rose
Hi Sandeep,
Very cool! FYI, This is very similar to a tool Ivana and I recently developed and donated to the opensbom org:https://github.com/opensbom-generator/sbom-composer😊
-Rose
|
By
Rose Judge
·
#1645
·
|
|
Re: SPDXMerge Tool
#spdx
Very cool Sandeep!
Thanks for sharing this!
Very cool Sandeep!
Thanks for sharing this!
|
By
Kate Stewart
·
#1644
·
|
|
SPDXMerge Tool
#spdx
Hi All,
We are excited to announce that we have open sourced our SBoM Merge tool on GitHub. This tool allows you to merge multiple Software Bills of Materials (SBOMs) into a single SBOM file in SPDX
Hi All,
We are excited to announce that we have open sourced our SBoM Merge tool on GitHub. This tool allows you to merge multiple Software Bills of Materials (SBOMs) into a single SBOM file in SPDX
|
By
Patil, Sandeep
·
#1643
·
|
|
Re: SPDX in GSoC 2023!
Hello all,
Akshat this side.
It's great to see SPDX again in the GSoC 2023!
I am looking to contribute to Specification Generator
I have gone through the SPEC Parser repository. Kindly help me get
Hello all,
Akshat this side.
It's great to see SPDX again in the GSoC 2023!
I am looking to contribute to Specification Generator
I have gone through the SPEC Parser repository. Kindly help me get
|
By
akshatcoder@...
·
#1642
·
|
|
Re: SPDX Generator with RefIDs and package hierarchy
I honestly thought the original question was about SPDX's format itself and not about tools used in certain situations.
From my side tern does a good job in generating SPDX docs for
I honestly thought the original question was about SPDX's format itself and not about tools used in certain situations.
From my side tern does a good job in generating SPDX docs for
|
By
Nisha Kumar
·
#1641
·
|
|
Re: SPDX Generator with RefIDs and package hierarchy
Hi Daniel,
I’m not sure I agree if you include commercial and open source tools. If you’re generating the information primarily from package manifests, there are a few tools out there that
Hi Daniel,
I’m not sure I agree if you include commercial and open source tools. If you’re generating the information primarily from package manifests, there are a few tools out there that
|
By
Gary O'Neall
·
#1640
·
|
|
Re: SPDX Generator with RefIDs and package hierarchy
Richard,
REA has effectively used SPDX and CycloneDX SBOM formats to conduct software supply chain risk assessments since 2021. I suggest using the latest SPDX SBOM version, 2.3.
Thanks,
Dick
Richard,
REA has effectively used SPDX and CycloneDX SBOM formats to conduct software supply chain risk assessments since 2021. I suggest using the latest SPDX SBOM version, 2.3.
Thanks,
Dick
|
By
Dick Brooks
·
#1639
·
|
|
Re: SPDX Generator with RefIDs and package hierarchy
Is SPDX actually useful as an SBoM specification? I tried to add
support into uSWID a few months ago and it was totally underspecified
compared to SWID.
Richard.
Is SPDX actually useful as an SBoM specification? I tried to add
support into uSWID a few months ago and it was totally underspecified
compared to SWID.
Richard.
|
By
Richard Hughes
·
#1638
·
|
|
Re: SPDX Generator with RefIDs and package hierarchy
So just to confirm with the community:
There is no single generator that can generate SPDX SBOMs, with dependency hierarchies, across different ecosystems (Python, Go, etc.) and for both containers &
So just to confirm with the community:
There is no single generator that can generate SPDX SBOMs, with dependency hierarchies, across different ecosystems (Python, Go, etc.) and for both containers &
|
By
daniel@...
·
#1637
·
Edited
|
|
Re: SPDX Generator with RefIDs and package hierarchy
Daniel
Have a look at SBOM4Python which generates an SBOM for an installed python module including all of its dependencies (direct or indirect). And look at SBOM2dot which generates a DOT file for
Daniel
Have a look at SBOM4Python which generates an SBOM for an installed python module including all of its dependencies (direct or indirect). And look at SBOM2dot which generates a DOT file for
|
By
Anthony Harrison
·
#1636
·
|