-
-
Notifications
You must be signed in to change notification settings - Fork 75
Closed
Description
As well as I explained in this merge request, SBOMs have to comply with NTIA, NIST and CRA (Cyber Resiliant Act) regulations, which require time stamping as a minimum requirement for SBOMs.
However, the merge command currently does not include timestamp metadata. The previous merge request proposes setting the date at the time of merging. This feature may need to be added to ensure SBOM compliance.
We could then add the merging of each SBOM's metadata.
Metadata
Metadata
Assignees
Labels
No labels