-
-
Notifications
You must be signed in to change notification settings - Fork 275
Open
Description
This is an EPIC (umbrella issue) for activities related to uploading Temurin SBOMs into a DependencyTrack instance (likely the one that Eclipse Foundation hosts). General top-level activities might be:
- Read what is required to upload an SBOM to sbom.eclipse.org (in this documentation)
- Define a project hierarchy for Temurin SBOMs ( per official release x each platform ? )
- Create a Github workflow that pulls the appropriate SBOMs from the Adoptium API matching the structure of the project hierarchy that has the ability to upload to DependencyTrack (see related/reusable workflow here)
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
In Progress