JReleaser · @jreleaser
179 followers · 101 posts · Server fosstodon.org

🔐 Create SBOMs for distributions and files via jreleaser.org/guide/latest/ref

#syft

Last updated 3 years ago

Andres Almiray · @aalmiray
637 followers · 307 posts · Server mastodon.social

Well this happened. is now capable of producing thanks to an integration with . You don't need Syft pre-installed on your environment, JReleaser takes care of that

jreleaser.org/guide/early-acce

#jreleaser #SBOMs #syft

Last updated 3 years ago

Andres Almiray · @aalmiray
631 followers · 292 posts · Server mastodon.social

SBOM support coming up next thanks to 's Java cataloger

#jreleaser #syft #sneakpeek

Last updated 3 years ago

Andres Almiray · @aalmiray
631 followers · 285 posts · Server mastodon.social

TIL that takes advantage of metadata embedded in a JAR (/META-INF/maven/*) to generate SBOMs. These files are automatically added by Maven during a build.

Glad I built a plugin for years ago to do the same

kordamp.org/kordamp-gradle-plu

#syft #maven #gradle

Last updated 3 years ago