Skip to content

EPIC: Upload Temurin SBOMs to DependencyTrack #4182

@smlambert

Description

@smlambert

This is an EPIC (umbrella issue) for activities related to uploading Temurin SBOMs into a DependencyTrack instance (likely the one that Eclipse Foundation hosts). General top-level activities might be:

  • Read what is required to upload an SBOM to sbom.eclipse.org (in this documentation)
  • Define a project hierarchy for Temurin SBOMs ( per official release x each platform ? )
  • Create a Github workflow that pulls the appropriate SBOMs from the Adoptium API matching the structure of the project hierarchy that has the ability to upload to DependencyTrack (see related/reusable workflow here)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    In Progress

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions