0 - Create plan for ISBOM rollout
based on the research findings here: https://about.gitlab.com/handbook/engineering/development/secure/tech-docs/data-model-for-dependencies-information/
for the specific objective of improving / updating / evolving our ISBOM to be something, we can export to CycloneDX and SPDX for a single project - what are the pre-requisite work and steps needed to accomplish that?
The next epic will be either cyclone DX or SPDX whichever is easier
MUST INCLUDE CONTAINERS
Auto-Summary 🤖
Discoto Usage
Points
Discussion points are declared by headings, list items, and single lines that start with the text (case-insensitive)
point:. For example, the following are all valid points:
#### POINT: This is a point* point: This is a point+ Point: This is a point- pOINT: This is a pointpoint: This is a **point**Note that any markdown used in the point text will also be propagated into the topic summaries.
Topics
Topics can be stand-alone and contained within an issuable (epic, issue, MR), or can be inline.
Inline topics are defined by creating a new thread (discussion) where the first line of the first comment is a heading that starts with (case-insensitive)
topic:. For example, the following are all valid topics:
# Topic: Inline discussion topic 1## TOPIC: **{+A Green, bolded topic+}**### tOpIc: Another topicQuick Actions
Action Description /discuss sub-topic TITLECreate an issue for a sub-topic. Does not work in epics /discuss link ISSUABLE-LINKLink an issuable as a child of this discussion
Last updated by this job
-
TOPIC Output extra CycloneDX artifact #343403 (comment 807813461)
- Delayed processing #343403 (comment 807813507)
- Maintenance concerns #343403 (comment 807813550)
- No backwards compatibility #343403 (comment 807813590)
- Splitting Dependency Scanning reports #343403 (comment 807813631)
- Reusable CycloneDX import #343403 (comment 808586380)
- CycloneDX output tested in analyzer projects #343403 (comment 808590708)
- Backwards compatible #343403 (comment 808598082)
- CycloneDX artifacts before full CycloneDX export #343403 (comment 809347217)
- How to generate CycloneDX Report #343403 (comment 816071919)
-
TOPIC Create an adapter #343403 (comment 807813718)
- Backwards compatibility #343403 (comment 807813757)
- Immediate processing #343403 (comment 807813792)
-
TOPIC Is the CycloneDX file format sufficient? #343403 (comment 807814090)
- Create our own custom binary file format #343403 (comment 807814147)
- Create a manifest file (parent file) which can link multiple files together #343403 (comment 807814208)
- TOPIC Migration plan #343403 (comment 809400401)
-
TOPIC Manifest file format #343403 (comment 820428718)
- What information do we need in the manifest file? #343403 (comment 820428804)
- TOPIC Where is the manifest needed? #343403 (comment 823201694)
Discoto Settings
---
summary:
max_items: -1
sort_by: created
sort_direction: ascending
See the settings schema for details.