On Wed, 9 Jul 2025, Dick Brooks wrote:

Congratulations. Any chance we will see an SBOM for curl in the future?

The "normal" curl release does not need an SBOM. It is just one thing and this one thing comes only from us: the curl release.

curl releases are done as source code tarballs with no third party code included.

There are some additional things we ship, like windows binaries at https://curl.se/windows/ and they contain 3rd party components. All the details for those are provided there, which should allow users to make an SBOM out of it in the preferred format of the day.

--

 / daniel.haxx.se || https://rock-solid.curl.dev
--
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html

Reply via email to