Skip to content

Commit

Permalink
Add a SBOM file in CycloneDX format
Browse files Browse the repository at this point in the history
Improve supply chain security by including a SBOM file with substituted values.

This will be used to construct a composite platform SBOM.

Signed-off-by: Richard Hughes <[email protected]>
  • Loading branch information
hughsie committed Nov 15, 2024
1 parent 0cc6860 commit b10b6a4
Showing 1 changed file with 41 additions and 0 deletions.
41 changes: 41 additions & 0 deletions sbom.cdx.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"version": 1,
"components": [
{
"type": "library",
"bom-ref": "pkg:github/Mbed-TLS/mbedtls@@VCS_TAG@",
"cpe": "cpe:2.3:a:Mbed-TLS:mbedtls:@VCS_TAG@:*:*:*:*:*:*:*",
"name": "mbedtls",
"version": "@VCS_VERSION@",
"description": "Implements cryptographic primitives, X.509 certificate manipulation and SSL/TLS and DTLS protocols",
"authors": [
{
"name": "@VCS_SBOM_AUTHORS@"
}
],
"supplier": {
"name": "The Mbed TLS Contributors"
},
"licenses": [
{
"license": {
"id": "Apache-2.0"
}
},
{
"license": {
"id": "GPL-2.0-or-later"
}
}
],
"externalReferences": [
{
"type": "vcs",
"url": "https://github.com/Mbed-TLS/mbedtls"
}
]
}
]
}

0 comments on commit b10b6a4

Please sign in to comment.