Issues
- 3
- 2
bom will leave cloned modules in tmp
#458 opened by puerco - 1
Support for Generating an SBOM for the Entire Kubernetes Environment, Including Namespace, Pods, Services, Images and Network Policy Details
#470 opened by RajikaJain - 13
- 5
Push to github release
#439 opened by puerco - 4
Support for SBOMs in (signed) in-toto attestations
#441 opened by puerco - 4
Support reading/writing SBOMs from OCI registries
#442 opened by puerco - 4
Refactor internals to use protobom
#440 opened by puerco - 4
Record module version
#438 opened by puerco - 0
Incorrect detection of license per file
#486 opened by kikofernandez - 7
Replace `golang.org/x/tools/go/vcs`
#338 opened by saschagrunert - 9
SPDX relationships like `DEPENDENCY_OF` and `TEST_DEPENDENCY_OF` seem to be not supported
#354 opened by maxhbr - 4
- 13
- 5
- 8
downloaded go modules are not being picked up by the go interpreter when bom generate runs
#202 opened by sandipanpanda - 3
typo maybe?
#394 opened by SD-13 - 11
Provide support for CycloneDX
#100 opened by VinodAnandan - 7
- 5
Release v0.5.1 of `bom generate` can panic while main has been fixed, could we get v0.5.2?
#385 opened by mtardy - 2
Support Go binaries in bom generate
#347 opened by micahhausler - 2
PackageFromDirectory segfault
#308 opened by howardjohn - 24
build a distroless base image to be used for bom based on apko and melange
#137 opened by developer-guy - 9
Add compose functionality
#168 opened by ivanayov - 7
Publish container image per release
#171 opened by saschagrunert - 0
Error When Installing With Published Command
#214 opened by jspeed-meyers - 1
- 0
SPDX2.2: bom generates SBOM with invalid value for packageVerificationCodeValue
#230 opened by surendrapathak - 3
Panic when building with both --image and --file
#240 opened by jaevans - 4
- 8
Fatal on scanning a dir
#182 opened by sbs2001 - 5
Don't use one HTTP request per license download
#193 opened by sbs2001 - 4
- 4
PackageName includes version string
#172 opened by anthonyharrison - 2
- 4
Allow to generate SBOM of specific SPDX version
#165 opened by sbs2001 - 4
Include License List Version Field.
#164 opened by sbs2001 - 4
- 0
Fix namespace in golang purls
#169 opened by sbs2001 - 4
SPDX 2.3 Support
#111 opened by puerco - 5
generate/sign SBOM attestation files and attach them to container image with cosign
#82 opened by developer-guy - 1
Crash when scanning scan on image
#148 opened by sbs2001 - 0
- 0
- 1
Docker image for `bom` is broken
#135 opened by sbs2001 - 2
bom runtime error
#127 opened by mdeicas - 5
- 4
Weird timestamp format in SPDX document
#98 opened by lumjjb - 2
Support additional output formats for SPDX
#103 opened by jdolitsky - 0