Skip to content

Add version info to layer Packages in SPDX reports - #1210

Merged
rnjudge merged 1 commit into
tern-tools:mainfrom
rnjudge:ntia-min-reqs
Feb 7, 2023
Merged

rnjudge merged 1 commit into
tern-tools:mainfrom
rnjudge:ntia-min-reqs

Conversation

@rnjudge

@rnjudge rnjudge commented Jan 26, 2023

Copy link
Copy Markdown
Contributor

The NTIA minimum requirements for an SBOM require that all Packages have version information. Since Tern represents container layers as SPDX Packages, these package elements must have version information in order to satisfy NTIA minimums. This commit adds version information to layer "Packages" using the layer indexes (i.e. the base OS layer has version "1")

Works towards #1205

Signed-off-by: Rose Judge rjudge@vmware.com

The NTIA minimum requirements for an SBOM require that all Packages have
version information. Since Tern represents container layers as SPDX
Packages, these package elements must have version information in order
to satisfy NTIA minimums. This commit adds version information to layer
"Packages" using the layer indexes (i.e. the base OS layer has version
"1")

Works towards tern-tools#1205

Signed-off-by: Rose Judge <rjudge@vmware.com>
@rnjudge
rnjudge merged commit 2e51f67 into tern-tools:main Feb 7, 2023
@rnjudge
rnjudge deleted the ntia-min-reqs branch July 20, 2023 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant