You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
First, I want to thank you for the amazing work you’ve done with REUSE! Most of my repositories (orgnization wise) are REUSE-compliant, and I really appreciate the tool’s help in managing licenses.
I’m relatively new to supply chain security concepts and I’m trying to understand how to integrate the SPDX SBOM and license data generated by the reuse spdx command into software supply chain attestations, particularly with Cosign or GitHub attestations. If I’m misunderstanding anything, I’d really appreciate your forgiveness and any guidance you can provide.
Questions:
How can the SPDX SBOM from reuse spdx be added to attestations in Cosign or GitHub?
What’s the best way to include licensing info (e.g., SPDX license files) in an attestation?
Does REUSE plan to support integrations with Cosign or GitHub attestations, or are there recommended workflows for this?
I’m sorry if I’m missing something. I’d greatly appreciate any examples or advice you can offer to help me understand how to integrate SPDX and licensing info into supply chain attestations.
Thanks again for your work and support!
The text was updated successfully, but these errors were encountered:
puria
changed the title
Request for Guidance on Integrating SPDX SBOM and License Info into Attestations
Request for guidance on integrating SPDX SBOM and license info into Github attestations
Dec 4, 2024
puria
changed the title
Request for guidance on integrating SPDX SBOM and license info into Github attestations
Request for guidance on integrating SPDX SBOM and license info into Github attestations (beta)
Dec 4, 2024
Hi REUSE team,
First, I want to thank you for the amazing work you’ve done with REUSE! Most of my repositories (orgnization wise) are REUSE-compliant, and I really appreciate the tool’s help in managing licenses.
I’m relatively new to supply chain security concepts and I’m trying to understand how to integrate the SPDX SBOM and license data generated by the
reuse spdx
command into software supply chain attestations, particularly with Cosign or GitHub attestations. If I’m misunderstanding anything, I’d really appreciate your forgiveness and any guidance you can provide.Questions:
reuse spdx
be added to attestations in Cosign or GitHub?I’m sorry if I’m missing something. I’d greatly appreciate any examples or advice you can offer to help me understand how to integrate SPDX and licensing info into supply chain attestations.
Thanks again for your work and support!
The text was updated successfully, but these errors were encountered: