Include language package manager (e.g. cargo
, npm
, go modules) information in SBOMs
#17423
Open
1 task done
Labels
Verification
brew install wget
. If they do, open an issue at https://github.com/Homebrew/homebrew-core/issues/new/choose instead.Provide a detailed description of the proposed feature
The
sbom.spdx.json
contains dependency information for dependencies managed bybrew
. We should include dependency information for those not managed bybrew
as well.What is the motivation for the feature?
More complete SBOMs. It will also improve our ability to track CVEs that affect formulae.
How will the feature be relevant to at least 90% of Homebrew users?
It probably won't be.
What alternatives to the feature have been considered?
The text was updated successfully, but these errors were encountered: