You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It would be great to port this feature to cdxgen v12 and enhance the current CLI to first detect project types, then generate BOMs using the appropriate container images before performing aggregation. This would improve the precision a bit at the cost of increased gen time (which is fine).
The text was updated successfully, but these errors were encountered:
The upcoming version of depscan v6 introduces the concept of BOM engines, with
CdxgenImageBasedGenerator
being one of them.https://github.com/owasp-dep-scan/dep-scan/blob/117d85be50c7df4c5059a5eddc284f7e918b69a2/packages/xbom-lib/src/xbom_lib/cdxgen.py#L250
It would be great to port this feature to cdxgen v12 and enhance the current CLI to first detect project types, then generate BOMs using the appropriate container images before performing aggregation. This would improve the precision a bit at the cost of increased gen time (which is fine).
The text was updated successfully, but these errors were encountered: