You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Right now our SBOMs only track the Go binary, but we include static assets via kodata today, and those aren't represented. I think for our SBOM(s) to be truly complete we need to include kodata as well.
This issue is stale because it has been open for 90 days with no
activity. It will automatically close after 30 more days of
inactivity. Keep fresh with the 'lifecycle/frozen' label.
Was talking to @puerco about having "layer" packages, and while it is probably overkill for what we have right now, it may make sense when we do this to note that we have a layer containing the Go binary and a layer containing the kodata files.
Right now our SBOMs only track the Go binary, but we include static assets via kodata today, and those aren't represented. I think for our SBOM(s) to be truly complete we need to include kodata as well.
cc @puerco @jdolitsky @imjasonh @jonjohnsonjr
The text was updated successfully, but these errors were encountered: