Skip to content

Additional SBOM report metadata #123

Open
@woodruffw

Description

@woodruffw

As of #109, our SBOM reports include a baseline of information about each package distribution and its vulnerabilities:

  • Package name
  • Package version
  • Any CycloneDX-generated metadata for each of the above
  • For each vulnerability:
    • Vulnerability ID (like PYSEC-*)
    • Human readable description
    • An "Upgrade" recommendation
    • Advisory versions for upgrade

It might be worth looking into iteratively expanding this information, using package/distribution metadata. Some potential inclusions would be:

  • Package author and/or maintainer
  • Package license
  • For each vulnerability:
    • Vulnerability "source" (i.e. PyPI, OSV, etc.)
    • Additional cross-referencing IDs/URLs (CVEs, etc.)
    • Additional weakness and vulnerability enumerations (CWEs, etc.)

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions