Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature Request] Create and release SBOMs for OpenSearch artifacts #16745

Open
der-eismann opened this issue Nov 29, 2024 · 1 comment
Open
Labels
Build Build Tasks/Gradle Plugin, groovy scripts, build tools, Javadoc enforcement. enhancement Enhancement or improvement to existing feature or request

Comments

@der-eismann
Copy link

der-eismann commented Nov 29, 2024

Is your feature request related to a problem? Please describe

Hey everyone! Maybe you've heart of SBOMs before - if not, it's a Software Bill of Materials listing all dependencies including versions that a project is using. This allows users to have quickly check if they are affected when info about a new vulnerability is released.
Some more info can be found here:
https://thenewstack.io/sbom-everywhere-the-openssf-plan-for-sboms/
https://cwiki.apache.org/confluence/display/COMDEV/SBOM

Describe the solution you'd like

There's an excellect Gradle plugin (https://github.com/CycloneDX/cyclonedx-gradle-plugin) that produces such SBOMs during the build process with lots of custom settings. These SBOMs can then be bundled with the released artifacts. JSON would be my preferred format.

Ideally this would be done for every component (OpenSearch, OS Dashboards etc), please let me know if I should open copies of this issue there as well.

Related component

Build

Describe alternatives you've considered

None

Additional context

No response

@der-eismann der-eismann added enhancement Enhancement or improvement to existing feature or request untriaged labels Nov 29, 2024
@github-actions github-actions bot added the Build Build Tasks/Gradle Plugin, groovy scripts, build tools, Javadoc enforcement. label Nov 29, 2024
@dblock dblock removed the untriaged label Jan 6, 2025
@dblock
Copy link
Member

dblock commented Jan 6, 2025

[Catch All Triage - 1, 2, 3, 4]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Build Build Tasks/Gradle Plugin, groovy scripts, build tools, Javadoc enforcement. enhancement Enhancement or improvement to existing feature or request
Projects
None yet
Development

No branches or pull requests

2 participants