alitheg opened a new issue, #1398: URL: https://github.com/apache/tooling-trusted-releases/issues/1398
Update the ATR client with SBOM-related functionality: - Generate an SBOM for a given artifact (API call - the file will appear in a new revision) - Augment it automatically (background task triggered on that file) - Download it to some staging area locally, and sign it interactively - Upload the signature to ATR We may want to add the ability to run the vulnerability scan too, which also edits the SBOM, but I don't think that's a necessary first step (and it would require more signing) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
