Branch
Hash :
e9668c8c
Author :
Date :
2025-05-27T08:50:34
Add a SBOM template in CycloneDX format (#1224) Improve supply chain security by including a SBOM file with substituted values. This will be used to construct a composite platform SBOM. Signed-off-by: Richard Hughes <rhughes@redhat.com> Co-authored-by: Eugene Kliuchnikov <eustas.ru@gmail.com>
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44
{
"_comment": "See https://cyclonedx.org/ for more details",
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"version": 1,
"metadata": {
"authors": [
{
"name": "@VCS_SBOM_AUTHORS@"
}
]
},
"components": [
{
"type": "library",
"bom-ref": "pkg:github/google/brotli@@VCS_TAG@",
"cpe": "cpe:2.3:a:google:brotli:@VCS_TAG@:*:*:*:*:*:*:*",
"name": "Brotli",
"version": "@VCS_VERSION@",
"description": "A generic-purpose lossless compression algorithm",
"authors": [
{
"name": "@VCS_AUTHORS@"
}
],
"supplier": {
"name": "Brotli developers"
},
"licenses": [
{
"license": {
"id": "MIT"
}
}
],
"externalReferences": [
{
"type": "vcs",
"url": "https://github.com/google/brotli"
}
]
}
]
}