dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Adding a Sigstore indicator to dependencies

Open robertlagrant opened this issue 1 year ago • 0 comments

Proposed Behavior:

Issue to explore DependencyTrack being able to indicate whether a dependency has a Sigstore signature detected. To better cyber risk assess the software supply chain.

See also: https://github.com/CycloneDX/specification/issues/155

robertlagrant avatar Aug 10 '22 10:08 robertlagrant