Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature: Allow one sbom to be the primary document in assemble action #128

Open
matglas opened this issue Dec 11, 2024 · 2 comments
Open

Comments

@matglas
Copy link
Contributor

matglas commented Dec 11, 2024

What I notice is that its only possible to assemble while settings the primary tags or the config and this is a limitation.

What I am looking for is to provide the primary component and add all the other boms as dependencies. At this point you are required to use the config even if you would have a proper root component and want to add the extra components from the SBOMs.

If there would be a --primary-component-file flag that allows you to base your file on that and add the other boms.

Interested to hear what others things about this process.

@matglas
Copy link
Contributor Author

matglas commented Dec 11, 2024

Another way to phrase this is the ability to do SBOM append. And add B to A. Where B is a dependency of A.

@riteshnoronha
Copy link
Contributor

I agree this also should be a mode of operation for the tool. Let me add this as a feature request, should not be that hard to implement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants