Hi all over in Ant land I am currently working on tooling to create CycloneDX SBOMs for Ant itself - and possibly other projects using Ant with manual dependency management (or Ivy at one point).
I've got a few questions to challenge my design decisions and questions about what people would expect from SBOMs for tarballs of binary releases - the later is what I expect more Ant users to consume than "just the jars" from Maven central. Before I go into more details, is the the correct list? Or security-discuss@community or ...? I have seen the comflunce pages on SBOMs but don't really know "where the community meets". Stefan
