You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Information about the images and their layers via properties is useful while generating SBoM for oci images. Trivy uses the following names.
aquasecurity:trivy:LayerDigest
aquasecurity:trivy:LayerDiffID
aquasecurity:trivy:ImageID
Syft uses the following
syft:location:0:layerID
syft:location:1:layerID
Instead of requesting another one for cdxgen and other orgs, could we come up with something generic using "org.opencontainers" etc? Example:
org.opencontainers.image.layer.digest
org.opencontainers.image.layer.id
org.opencontainers.image.id
The text was updated successfully, but these errors were encountered:
jkowalleck
changed the title
Generic top level taxonomy to describe some oci images and layers
[PROPOSAL] Generic namespace for describing OCI images and layers
Jun 7, 2023
who would own this OCI-related namespace, then? Is there any org or a general committee? did you get in touch with opencontainers(Open Container Initiative), maybe they have such a thing already?
where is the taxonomy for this namespace? just having it registered/reserved and having no FFA taxonomy, that serves no purpose. So as long as there is no peer-reviewed and general agreed taxonomy details, I'd veto this proposal.
I am concerned that this would create a non-standard nobody would use, so there should be consensus about the details of this taxonomy, first.
Information about the images and their layers via properties is useful while generating SBoM for oci images. Trivy uses the following names.
Syft uses the following
Instead of requesting another one for cdxgen and other orgs, could we come up with something generic using "org.opencontainers" etc? Example:
The text was updated successfully, but these errors were encountered: