Re: Software Bill of Materials (SBOM)

From: Julian Coccia <julian(dot)coccia(at)scanoss(dot)com>
To: Кристина Валентей <klsst1nv0(at)gmail(dot)com>, "pgsql-general(at)lists(dot)postgresql(dot)org" <pgsql-general(at)lists(dot)postgresql(dot)org>
Subject: Re: Software Bill of Materials (SBOM)
Date: 2024-01-13 11:10:08
Message-ID: PR3P250MB014902478C3AC740F77C68E0FA6E2@PR3P250MB0149.EURP250.PROD.OUTLOOK.COM
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

Hi Cristina,

Have you tried SCANOSS?

To install:

pip3 install scanoss

To generate your SBOM (SPDX lite):

scanoss-py scan --format spdxlite DIRECTORY/

Alternatively, in CycloneDX format instead:

scanoss-py scan --format cyclonedx DIRECTORY/

Hope this helps.

Regards,
Julian

From: Кристина Валентей <klsst1nv0(at)gmail(dot)com>
Date: Saturday, 13 January 2024 at 12:03
To: pgsql-general(at)lists(dot)postgresql(dot)org <pgsql-general(at)lists(dot)postgresql(dot)org>
Subject: Software Bill of Materials (SBOM)
Good afternoon.
I'm looking for a way to build sbom files for assembly postgresql, to perform software composition analysis (SCA).

Please, tell me how can I do this?

Thank you.

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Adrian Klaver 2024-01-13 16:29:43 Re: How to redirect output from PostgreSQL pg_recvlogical to a file or a pipe?
Previous Message Tom Lane 2024-01-13 06:08:49 Re: COBOL PRECOMPILER for PostGreSQL