Open
Description
Pending #7 and having a 'latest' vdr.json artifact to be able to retrieve, we can identify the various ways we would like to utilize this report:
- Link to it from GA release SBOMs (using the CycloneDX format that can link these documents)
- Use it as an input to help generate the release blog post (which has a manually created CVE table at the moment)
- Consume it as part of a regular run to verify its validity (and mirror what our enterprise consumers would experience)
- etc.
Metadata
Metadata
Assignees
Labels
No labels