Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate SBOM from SIF Image #190

Closed
tri-adam opened this issue Mar 28, 2022 · 0 comments · Fixed by #227
Closed

Generate SBOM from SIF Image #190

tri-adam opened this issue Mar 28, 2022 · 0 comments · Fixed by #227
Labels
roadmap Features / changes that are scheduled to be implemented

Comments

@tri-adam
Copy link
Member

To support users of SingularityCE who are investing in their software supply chain security, we should look at adding support for users to generate a software bill of materials (SBOM) from a given SIF image, and (perhaps optionally) embed the SBOM itself within a SIF image.

We should look at integrating with an existing, open source tool to do the actual SBOM generation. We are already using Goreleaser to generate our releases, which supports SBOM generation and uses Anchore Syft under the hood (ref). This would seem like a compelling place to start.

This support could be bundled into singularity, siftool, and/or syft itself. @luhring, would there be any appetite to add SIF support directly within Syft? Happy to assist with effort to make that happen, if it makes sense from a user perspective.

@tri-adam tri-adam added the roadmap Features / changes that are scheduled to be implemented label Mar 28, 2022
@tri-adam tri-adam mentioned this issue Sep 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
roadmap Features / changes that are scheduled to be implemented
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant