Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request for guidance on integrating SPDX SBOM and license info into Github attestations (beta) #1115

Open
puria opened this issue Dec 4, 2024 · 0 comments

Comments

@puria
Copy link

puria commented Dec 4, 2024

Hi REUSE team,

First, I want to thank you for the amazing work you’ve done with REUSE! Most of my repositories (orgnization wise) are REUSE-compliant, and I really appreciate the tool’s help in managing licenses.

I’m relatively new to supply chain security concepts and I’m trying to understand how to integrate the SPDX SBOM and license data generated by the reuse spdx command into software supply chain attestations, particularly with Cosign or GitHub attestations. If I’m misunderstanding anything, I’d really appreciate your forgiveness and any guidance you can provide.

Questions:

  1. How can the SPDX SBOM from reuse spdx be added to attestations in Cosign or GitHub?
  2. What’s the best way to include licensing info (e.g., SPDX license files) in an attestation?
  3. Does REUSE plan to support integrations with Cosign or GitHub attestations, or are there recommended workflows for this?

I’m sorry if I’m missing something. I’d greatly appreciate any examples or advice you can offer to help me understand how to integrate SPDX and licensing info into supply chain attestations.

Thanks again for your work and support!

@puria puria changed the title Request for Guidance on Integrating SPDX SBOM and License Info into Attestations Request for guidance on integrating SPDX SBOM and license info into Github attestations Dec 4, 2024
@puria puria changed the title Request for guidance on integrating SPDX SBOM and license info into Github attestations Request for guidance on integrating SPDX SBOM and license info into Github attestations (beta) Dec 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant