k8-sig's BOM #7170
k8-sig's BOM
#7170
-
Hi, I wanted to ask about the functionality relationship between ORT and https://github.com/kubernetes-sigs/bom:
Thanks. |
Beta Was this translation helpful? Give feedback.
Answered by
sschuberth
Jun 21, 2023
Replies: 1 comment 1 reply
-
Looks like the So bottom line, |
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
dgutson
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Looks like the
bom
tool basically accepts two types of input: containers and directories / files. Only if the directory happens to contain a Go module, package-level dependencies are determined. I.e.bom
completely lacks ORT's package-manager support. If the directory is not a Go module, its files are being listed as part of the SPDX BOM.So bottom line,
bom
rather seems to complement ORT than offering the same functionality, and eventuallybom
could be used to implement #1833.