-
-
Notifications
You must be signed in to change notification settings - Fork 28
Adds NTIA SBOM Validator #25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Force push was just to add the DCO message :) |
tools.yaml
Outdated
@@ -2177,6 +2177,13 @@ | |||
categories: | |||
- opensource | |||
- author | |||
- name: NTIA Validator for CycloneDX | |||
publisher: FOSSA | |||
description: Ensure your CycloneDX SBOM meets NTIA requirements BEFORE you submit. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Unsure of what "BEFORE you submit" means. Relative to what process? Borrowing from the "key features" section of the tool website, perhaps the description would better include the bullets from there:
- Detailed validation feedback
- Dependency graph visualization and validation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the feedback. I've updated the description to explain a little better :)
Note: The CycloneDX team is in the process of migrating the legacy Tool Center datafile (tools.yaml) to the new Tool Center v2 format (tools.json). This work is expected to be complete by the end of May. Once the migration to the v2 datafile is complete:
Information about the new Tool Center v2 schema can be found at: https://cyclonedx.github.io/tool-center/ |
Signed-off-by: Sara <[email protected]>
Signed-off-by: Sara <[email protected]>
This is a tool for validating CycloneDX SBOMs against the NTIA's Minimum Required Elements for an SBOM