What is status and timeline of SBOM work? #22966
Replies: 4 comments 8 replies
|
There should be a I believe |
|
For anyone coming from Google Search. As per bazel-contrib/rules_python#2054 (comment) and aspect-build/rules_js#1842 (comment) and the README at It seems https://github.com/bazel-contrib/supply-chain is the latest initiative effort in this space. |
|
Hi Team, I see this thread with no updates. Is there work going on fixing SBOM created by Bazel as currently GO and OS related packages are identified nothing else. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hi there,
SBOM is becoming increasingly important for all organizations, but Bazel still doesn't seem to have working SBOM support. I've seen this update: https://www.youtube.com/watch?v=9O-pr_yhjMI, and noticed that SBOM has been dropped from the bazel roadmap for this year.
From what I can piece together, the current state of play is:
PackageInfofrom imported packages bazel-contrib/rules_jvm_external#1196rules_licensePackageInfofrom imported dependencies bazel-contrib/rules_python#2054PackageInfofrom imported rules aspect-build/rules_js#1842The rules_license rules and bazel reference implementations are useful, thank you for that!
Is there still work to be upstreamed? And if so, what is the timeline for that? Or should we be rolling our own code to work around the gaps?
@aiuto
Thanks, Chris
All reactions