tac icon indicating copy to clipboard operation
tac copied to clipboard

Share OSSF project inventory with downstream consumers for incident response

Open sevansdell opened this issue 1 year ago • 0 comments

After all the projects are done self-identifying the initial stage they are in, I propose we adjust the incubating project lifecycle to post an SBOM on their github repo, maintain updating it with some frequency, and include a purl for software identification.

sevansdell avatar Apr 04 '24 19:04 sevansdell