alitheg opened a new issue, #1398:
URL: https://github.com/apache/tooling-trusted-releases/issues/1398

   Update the ATR client with SBOM-related functionality:
   
   - Generate an SBOM for a given artifact (API call - the file will appear in 
a new revision)
   - Augment it automatically (background task triggered on that file)
   - Download it to some staging area locally, and sign it interactively
   - Upload the signature to ATR
   
   We may want to add the ability to run the vulnerability scan too, which also 
edits the SBOM, but I don't think that's a necessary first step (and it would 
require more signing)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to