syft icon indicating copy to clipboard operation
syft copied to clipboard

timestamp in JSON Syft files

Open edhinard opened this issue 1 year ago • 0 comments

What would you like to be added: A date or timestamp in JSON Syft files.

Why is this needed: Our goal is to track evolution of VM. For that purpose we are comparing JSON Syft files and JSON Grype files. And the creation time of Syft files is currently used due to the lack of timestamp. Unfortunately, file metadata (including dates) are not perennial.

Additional context: This evolution would break the "Reproducible SBOM" requirement stated in #1100

Maybe have an optional timestamp.

edhinard avatar Feb 09 '24 09:02 edhinard