feat: use originator logic to fill supplier#1980
Merged
Merged
Conversation
Signed-off-by: Christopher Phillips <christopher.phillips@anchore.com>
Benchmark Test ResultsBenchmark results from the latest changes vs base branch |
Signed-off-by: Christopher Phillips <christopher.phillips@anchore.com>
Signed-off-by: Christopher Phillips <christopher.phillips@anchore.com>
kzantow
reviewed
Jul 31, 2023
Contributor
Author
|
Update the root package to have supplier as noassertion since this is a manually synthesized package as part of the source object |
wagoodman
reviewed
Aug 1, 2023
Contributor
There was a problem hiding this comment.
was this updated intentionally?
kzantow
approved these changes
Aug 1, 2023
Contributor
kzantow
left a comment
There was a problem hiding this comment.
👍 -- per discussion, just add a NOASSERTION supplier to the root package
Signed-off-by: Christopher Phillips <christopher.phillips@anchore.com>
This was referenced Aug 15, 2023
Closed
Closed
Open
Closed
This was referenced Aug 28, 2023
Closed
GijsCalis
pushed a commit
to GijsCalis/syft
that referenced
this pull request
Feb 19, 2024
* feat: use Originator to fill supplier for NTIA minimum --------- Signed-off-by: Christopher Phillips <christopher.phillips@anchore.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Syft should be filling in the supplier information to meet NTIA minimum standards for SPDX sbom generated by the tool.
Partially Addressing #1961
There are additional refinements we can make where supplier can get it's own function when we determine a good fence for when one field should specify one value vs another:
A good example:
Supplier
Originator
In this case
NOASSERTIONis returned when: