Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Standardize output of bomber as VDR output #114

Open
djschleen opened this issue Jan 12, 2023 · 3 comments
Open

Standardize output of bomber as VDR output #114

djschleen opened this issue Jan 12, 2023 · 3 comments
Assignees
Labels
enhancement New feature or request question Further information is requested
Milestone

Comments

@djschleen
Copy link
Member

djschleen commented Jan 12, 2023

Investigate bomber loading a CycloneDX formatted SBOM and output the same file enriched with vulnerability information.

@djschleen djschleen added the enhancement New feature or request label Jan 12, 2023
@djschleen djschleen self-assigned this Jan 12, 2023
@djschleen djschleen added the question Further information is requested label Feb 10, 2023
@djschleen
Copy link
Member Author

This is going to be a strange one. We may be able to get a bit of lift out of this, but VEX has a lot of context needed around it that possibly can't be easily automated.

@mirxcle mirxcle added this to the 1.0.0 milestone Apr 17, 2023
@mirxcle mirxcle changed the title VEX Support Standardize output of bomber as VDR output Apr 17, 2023
@garethr
Copy link
Contributor

garethr commented May 9, 2023

I jus started hacking on this, specifically to produce a CycloneDX VDR and have the basics working. What I'm missing is the BOMRef information. I note Package has a Reference property but this isn't currently populated? Any thoughts on populating that? I wanted to check before I take a run at it, as it's a bit into the internals vs just writing a rendered.

@djschleen
Copy link
Member Author

Hey @garethr i need to get notifications of messages turned on. I started down the road on a branch, do you have a link to what you've been working on?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request question Further information is requested
Development

No branches or pull requests

3 participants