cyclonedx-dotnet
cyclonedx-dotnet copied to clipboard
Optionally support adding nuget package files to BOM
For some integrity use cases it would be beneficial to include the files, and hashes, that are brought in by nuget packages.
This can definitely be helpful. One of the side-effect scenarios I can imagine this can be used for - generating WDAC templates for a product directly from the SBOM files (so no blessed pre-installed machine needed any more).
This issue is stale because it has been open for 3 months with no activity.