What is status and timeline of SBOM work? #22966
Replies: 2 comments 8 replies
-
Since @aiuto is no longer in the Bazel team, the SBOM work has unfortunately been deprioritized. But regarding supply chain security, we are working with the community on BCR provenance (see this doc). /cc @fweikert |
Beta Was this translation helpful? Give feedback.
-
There should be a I believe |
Beta Was this translation helpful? Give feedback.
-
Hi there,
SBOM is becoming increasingly important for all organizations, but Bazel still doesn't seem to have working SBOM support. I've seen this update: https://www.youtube.com/watch?v=9O-pr_yhjMI, and noticed that SBOM has been dropped from the bazel roadmap for this year.
From what I can piece together, the current state of play is:
PackageInfo
from imported packages bazel-contrib/rules_jvm_external#1196rules_license
PackageInfo
from imported dependencies rules_python#2054PackageInfo
from imported rules aspect-build/rules_js#1842The rules_license rules and bazel reference implementations are useful, thank you for that!
Is there still work to be upstreamed? And if so, what is the timeline for that? Or should we be rolling our own code to work around the gaps?
@aiuto
Thanks, Chris
Beta Was this translation helpful? Give feedback.
All reactions