Hi all

over in Ant land I am currently working on tooling to create CycloneDX
SBOMs for Ant itself - and possibly other projects using Ant with manual
dependency management (or Ivy at one point).

I've got a few questions to challenge my design decisions and questions
about what people would expect from SBOMs for tarballs of binary
releases - the later is what I expect more Ant users to consume than
"just the jars" from Maven central.

Before I go into more details, is the the correct list? Or
security-discuss@community or ...? I have seen the comflunce pages on
SBOMs but don't really know "where the community meets".

Stefan

Reply via email to