elemental
elemental copied to clipboard
Software bill of materials (SBOM)
(This is created as an elemental
issue simply because we don't have a better place for Elemental (the product) )
Elemental Teal should be accompanied with a "Software Bill Of Materials" (SBOM) to document the software supply chain.
Apparently Kubewarden is using CLO Monitor to visualize their SBOM efforts.
- reach out to Kubewarden team to learn about their SBOM efforts
- create a document (github issue/epic) on how to implement this for Elemental Teal
This is the PR that aded the sbom to kubewarden. Seems simple enough: https://github.com/kubewarden/kubewarden-controller/pull/246
https://github.com/rancher/elemental-operator/pull/160 for github provided images on elemental-operator
closing as done
PR reverted: https://github.com/rancher/elemental-operator/pull/191
Dont really understand why it could not find the command. Will try in a separate repo to see what is going on.
Just for the record: https://fosdem.org/2023/schedule/event/sbom_key_ingredients/