Skip to content

Improve SBOM graph VEX freshness gates#1537

Open
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/sbom-graph-vex-freshness
Open

Improve SBOM graph VEX freshness gates#1537
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/sbom-graph-vex-freshness

Conversation

@danyili2632
Copy link
Copy Markdown

Summary

  • add dependency graph completeness gates so flat-listed transitive components cannot be scored as complete SBOM evidence
  • add VEX credibility fields for verification status, stale entries, verifier, and evidence reference
  • add SBOM freshness and trustworthiness checks for age, CVE scan currency, build provenance, signer identity, and report output

Bounty

Addresses #1535.

I have read and agree to the CONTRIBUTING.md bounty terms. Preferred payment method can be provided privately after maintainer acceptance.

Validation

  • git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant