-
Spike
-
Resolution: Unresolved
-
Minor
-
None
-
None
-
None
Once Image Builder starts generating and providing SBOM for images, it would be great to make use of it for cloud images in the respective target cloud environment.
The purpose of this spike is to determine if there is some existing standard (or plan) for making SBOM available with the cloud image in any of the cloud environments supported by Image Builder (AWS, GCP, Azure).
The basic idea would be to attach the SBOM data to the imported cloud image as part of the import process.
GCP has https://cloud.google.com/artifact-analysis/docs/upload-sboms