Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[EKS] [request]: Generate SBOMs for release artifacts #1734

Open
stevehipwell opened this issue May 4, 2022 · 3 comments
Open

[EKS] [request]: Generate SBOMs for release artifacts #1734

stevehipwell opened this issue May 4, 2022 · 3 comments
Labels
EKS Amazon Elastic Kubernetes Service Proposed Community submitted issue

Comments

@stevehipwell
Copy link

Community Note

  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment

Tell us about your request
I'd like all artifacts created for EKS to have a secure SBOM generated so we can track the content of them. The SBOM should probably be in a number of formats but the OpenSSF SPDX format would be essential.

Which service(s) is this request for?
EKS.

Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?
I'd like to be able to validate and review the SBOM for EKS artifacts.

Are you currently working around this issue?
n/a

Additional context
This is related to #43 for storing container image SBOMs in ECR.

Attachments
n/a

@stevehipwell stevehipwell added the Proposed Community submitted issue label May 4, 2022
@mikestef9 mikestef9 added the EKS Amazon Elastic Kubernetes Service label May 4, 2022
@ecki
Copy link

ecki commented Jun 8, 2022

Is the issue in „additional context“ the right one?

@stevehipwell
Copy link
Author

Is the issue in „additional context“ the right one?

@ecki I'm making the assumption that once ECR can store image signatures it could also store SBOMs.

@ecki
Copy link

ecki commented Jun 8, 2022

Ah yes, Oras uses both types as explicite samples for the artifacts spec.
The link text confused me I thought it was about a request for sbom in ECR, but all good now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
EKS Amazon Elastic Kubernetes Service Proposed Community submitted issue
Projects
None yet
Development

No branches or pull requests

3 participants