mirror of
				https://github.com/google/brotli
				synced 2025-10-30 07:50:02 +08:00 
			
		
		
		
	Add a SBOM template in CycloneDX format (#1224)
Improve supply chain security by including a SBOM file with substituted values. This will be used to construct a composite platform SBOM. Signed-off-by: Richard Hughes <rhughes@redhat.com> Co-authored-by: Eugene Kliuchnikov <eustas.ru@gmail.com>
This commit is contained in:
		
							
								
								
									
										44
									
								
								sbom.cdx.json
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										44
									
								
								sbom.cdx.json
									
									
									
									
									
										Normal file
									
								
							| @ -0,0 +1,44 @@ | ||||
| { | ||||
|   "_comment": "See https://cyclonedx.org/ for more details", | ||||
|   "bomFormat": "CycloneDX", | ||||
|   "specVersion": "1.6", | ||||
|   "version": 1, | ||||
|   "metadata": { | ||||
|     "authors": [ | ||||
|       { | ||||
|         "name": "@VCS_SBOM_AUTHORS@" | ||||
|       } | ||||
|     ] | ||||
|   }, | ||||
|   "components": [ | ||||
|     { | ||||
|       "type": "library", | ||||
|       "bom-ref": "pkg:github/google/brotli@@VCS_TAG@", | ||||
|       "cpe": "cpe:2.3:a:google:brotli:@VCS_TAG@:*:*:*:*:*:*:*", | ||||
|       "name": "Brotli", | ||||
|       "version": "@VCS_VERSION@", | ||||
|       "description": "A generic-purpose lossless compression algorithm", | ||||
|       "authors": [ | ||||
|         { | ||||
|           "name": "@VCS_AUTHORS@" | ||||
|         } | ||||
|       ], | ||||
|       "supplier": { | ||||
|         "name": "Brotli developers" | ||||
|       }, | ||||
|       "licenses": [ | ||||
|         { | ||||
|           "license": { | ||||
|             "id": "MIT" | ||||
|           } | ||||
|         } | ||||
|       ], | ||||
|       "externalReferences": [ | ||||
|         { | ||||
|           "type": "vcs", | ||||
|           "url": "https://github.com/google/brotli" | ||||
|         } | ||||
|       ] | ||||
|     } | ||||
|   ] | ||||
| } | ||||
		Reference in New Issue
	
	Block a user
	 Richard Hughes
					Richard Hughes