v4.1.1 - Use Syft for SBOM #109
JeroenKnoops
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Use Syft for generating SBOM
You can create a SPDX file. This feature is using Anchore Syft.
Add
sbom: true
to the arguments and asbom-spdx.json
file is created.The filename is exported as output in
sbom-file
.See: https://github.com/philips-software/docker-ci-scripts#with-sbom
Attach SBOM to Image
When you are creating the SBOM file and you provided the sign arguments and cosign environment variables, the SBOM file will be attached to the image.
You can verify the provenance by doing the following thing:
Major change
What's Changed
New Contributors
Full Changelog: v4.1.0...v4.1.1
This discussion was created from the release v4.1.1 - Use Syft for SBOM.
Beta Was this translation helpful? Give feedback.
All reactions