Software Bill of Materials (SBOM)
Had a chat in the Continuous Delivery Foundation (CDF) working group on supply chain.
There was general interest in the idea of scoring sboms.
SBOM sources:
- Parth Patel has a public bucket of sboms from GHCR
- jenkins-x and tekton both generate sboms.
- https://github.com/spdx/spdx-examples
- John Speed Meyers (jsmeyers@chainguard.dev) has a pile he got from sourceforge.
- Chainguard has really good ones for their images.