Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow to list SBOMs created by the tools by package #12

Open
sschuberth opened this issue Sep 4, 2023 · 3 comments
Open

Allow to list SBOMs created by the tools by package #12

sschuberth opened this issue Sep 4, 2023 · 3 comments

Comments

@sschuberth
Copy link

Is your feature request related to a problem? Please describe.

Mostly, an auto-generated SBOM can only be as good as the metadata provided the project / packages. As such it might be unfair to compare tools solely based on their SBOM quality scores as they're not necessarily being run on the same packages.

Describe the solution you'd like

For a given project / package, it should be possible to list all the SBOMs and their scores for the respective tools. That way one can quickly see which tool is providing the best SBOM for a given fixed input.

Describe alternatives you've considered

Another way to emphasize that a plain quality score based comparison might be unfair would be to clearly show for each tool which package managers / build systems / ecosystems it supports. Users might prefer a single slightly "worse" polyglot tool over multiple "better" specialized tools for usage simplicity.

Additional context

Looking at https://sbombenchmark.dev/, it currently seems like "som4python" would be the best overall tool, but as the name suggests it's for Python projects only, and from a user perspective it makes little sense to directly compare this to container-only tools like "Syft".

@surendrapathak
Copy link
Collaborator

Thanks for the feedback @sschuberth . Let us evaluate this and get back to you.

@sschuberth
Copy link
Author

Any update on the matter, @surendrapathak?

@surendrapathak
Copy link
Collaborator

Hey @sschuberth , Sorry I dropped the ball on this one and we are in the middle of some key releases. Let me get back to you in two weeks on this issue. Thanks for your patiences.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants