Replies: 1 comment 2 replies
-
Currently, We have developed a website, https://sbombenchmark.dev/, to assist in evaluating open source SBOM generators by comparing their outputs for the same repository. This site provides a rough estimate of the quality of the SBOM generated by each tool. Ensuring accurate dependency data in your SBOM is a challenging problem to solve. One potential approach is to prepare golden-master lists of components and versions for repositories. These lists can be used by Golden master files need not be a complete authoritative set of components and versions belonging to a project. There could be multiple such files e.g one could have only direct dependencies, one could have transitive of a single component. etc. These could then be used to rank OSS SBOM generators based on certain criteria's that would be useful. We welcome any suggestions for better approaches and are open to discussions on this topic. @surendrapathak any more ideas that we discussed. |
Beta Was this translation helpful? Give feedback.
-
The tool has a lot of checks for various kinds of things, but it looks like it is missing one which comes across very quickly when you compare sbom-generating tools: not all tools identify all the components. It looks to me like there is quite substantial differences, and I am sure you have already run into this.
Scoring different tools outputs against expected components isn't a straightforward check to implement, so I was mostly curious on your take of caring (or not) for this aspect.
Beta Was this translation helpful? Give feedback.
All reactions