Skip to content

Merge produces non-compliant SBOM #438

@Nowcide

Description

@Nowcide

As well as I explained in this merge request, SBOMs have to comply with NTIA, NIST and CRA (Cyber Resiliant Act) regulations, which require time stamping as a minimum requirement for SBOMs.

However, the merge command currently does not include timestamp metadata. The previous merge request proposes setting the date at the time of merging. This feature may need to be added to ensure SBOM compliance.

We could then add the merging of each SBOM's metadata.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions