cyclonedx-cli
cyclonedx-cli copied to clipboard
Add support for component integrity checks
trafficstars
When a component has been included with hashes it would be great to be able to report on component hashes compared to publicly available component hashes. i.e. a component with a nuget package url could compare the recorded hash to what is reported by nuget.org