Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Example product-level SBOM #5

Merged
merged 2 commits into from
Aug 1, 2024
Merged

Example product-level SBOM #5

merged 2 commits into from
Aug 1, 2024

Conversation

mprpic
Copy link
Member

@mprpic mprpic commented Jun 24, 2024

This is a mock product-level SBOM that includes a node that represents a product, here a hypothetical RHEL 99.9 that consists of exactly one openssl RPM).

This uses the same style of referencing to other SBOMs as #3, but I'm happy to rework it to use DocumentRef if we choose that as a way to refer to other documents.

@mprpic mprpic requested a review from twaugh June 24, 2024 19:20
@mprpic mprpic force-pushed the example-product-sbom branch from 3b10ae3 to bdb7df5 Compare July 30, 2024 21:36
@mprpic
Copy link
Member Author

mprpic commented Jul 30, 2024

@twaugh I reworked this to pinpoint a specific RHEL version. This is now essentially an example of a release-time, product-level SBOM that describes a component and the product it belongs to. It only points to the SRPM with the understanding that the https://github.com/RedHatProductSecurity/security-data-guidelines/blob/main/sbom/examples/rpm/openssl-3.0.7-18.el9_2.spdx.json SBOM is the referred component-level SBOM.

@mprpic mprpic merged commit ae32979 into main Aug 1, 2024
1 check passed
@mprpic mprpic mentioned this pull request Aug 1, 2024
@mprpic mprpic deleted the example-product-sbom branch August 16, 2024 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants