Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integration / Alignment with CDXGen #8278

Open
mkurzman opened this issue Feb 14, 2024 · 2 comments
Open

Integration / Alignment with CDXGen #8278

mkurzman opened this issue Feb 14, 2024 · 2 comments
Labels
analyzer About the analyzer tool question An issue that is actually a question reporter About the reporter tool

Comments

@mkurzman
Copy link

Hi,
it seems the development activities for https://github.com/CycloneDX/cdxgen were intensified in 2023 and ongoing.
Is there a way to collaborate / align to use the benefits of CDXGen and join forces in cases where Package Managers or setup are not supported by the ORT analyzer yet?
Marcel

@sschuberth sschuberth added question An issue that is actually a question analyzer About the analyzer tool reporter About the reporter tool labels Feb 14, 2024
@prabhu
Copy link

prabhu commented May 31, 2024

I would be happy to support this. Please also consider:

  • blint - A new sbom and linting tool for binaries
  • depscan - A nextgen SCA tool

@sschuberth
Copy link
Member

Thanks @prabhu for your offer to help. I believe it would be beneficial to first understand more about the capabilities of the different tools, maybe also not limited to ORT and CDXGen.

Which brings me back to a long-standing wish of mine to have a service that takes some Git repository to analyze / scan, runs various SCA / SBOM tools on it, and compares the results.

Something like a Jenkins instance hosted by a "neutral" party would work for that, where we run jobs from Jenkinsfiles that are hosted in some Open Source repository that people can contribute to. Maybe we should reach out to Linux Foundation (ACT, OpenChain) or OWASP to check whether they would be willing to host such an instance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
analyzer About the analyzer tool question An issue that is actually a question reporter About the reporter tool
Projects
None yet
Development

No branches or pull requests

3 participants