Replies: 2 comments
-
These questions posted on the Federal Acquisition Regulation are interesting. Maybe a future version of tools could have a specific mode to generate compliant BoMs? |
Beta Was this translation helpful? Give feedback.
0 replies
-
Our organization switched from a mismatch of tooling (cyclonedx-maven-plugin, syft, trivy, etc) to using cdxgen due to its breadth and consistency of supported languages / package managers, as well as it's streamlined integration to Dependency Track (helping to simplify a lot of manual steps in our CI process). |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We would love to hear more about the challenges that prevented the adoption of cdxgen in your organization/team. Some points that came to our attention recently.
Are there any other observations/comments that could help us improve?
Beta Was this translation helpful? Give feedback.
All reactions