Uploaded image for project: 'Clair'
  1. Clair
  2. CLAIRDEV-78

SBOM: Add the ability for claircore to produce SPDX format SBOMs

XMLWordPrintable

    • Icon: Feature Feature
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • indexer, indexer-api, matcher
    • None

      Currently, the result of indexing is an index report, this is a clair-specific format that describes the packages/repos/distributions/environments within the examined filesystem(s). We would like to be able to offer the ability to return this index report in a well-known SBOM format, specifically SPDX.

      SPDX is the blessed format for SBOM generation for Red Hat (https://spaces.redhat.com/display/~pveillar/Mastery%3A+Security+Engineer+-+SBOM).

      Care has to be taken to ensure the SBOM output produced by the indexer is able to be ingested by Clair's matching machinery.

      Wiki notes: https://spaces.redhat.com/display/CLAIR/SBOM+notes

              Unassigned Unassigned
              jcroslan@redhat.com Joseph Crosland
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: