Skip to content

Vulnerability insights through SBOM #1590

Answered by tormath1
thomasvandeweijer asked this question in Q&A
Discussion options

You must be logged in to vote

Hello, SBOM is created based on the generic image content1 so it should not have the build tools listed inside (e.g: you can't find go or rust inside the SBOM file).

I don't have enough knowledge on this topic to know if SBOM is the right source for vulnerability detection but looking at the file content and its integration with tools like trivy it seems to be the best source for doing this.

There are two alternatives ways to get included packages versions:

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@thomasvandeweijer
Comment options

Answer selected by thomasvandeweijer
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants