-
Notifications
You must be signed in to change notification settings - Fork 25
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #75 from joshbressers/20240911-faq
Add a simple FAQ
- Loading branch information
Showing
1 changed file
with
26 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
# SBOM Everywhere Catalog FAQ | ||
|
||
## What is the SBOM Catalog? | ||
The OpenSSF has a working group called [SBOM Everywhere](https://github.com/ossf/sbom-everywhere), one of the projects this group is working on is a place to catalog as much SBOM related information as possible. Because the OpenSSF has a focus on open source, we’re doing it as an open source project! The goal is to capture anything that’s SBOM related and make it easy to find. Projects, documents, standards, working groups, anything that could be useful. | ||
|
||
## How do I access and use the tool? | ||
The SBOM catalog can be seen at https://sbom-catalog.openssf.org/ - It’s actually two tools, the Wiki and the catalog. The Wiki is to capture more static information like documents and standards. Our goal is to link to as many things as we can. | ||
|
||
The Catalog is where we can add tooling with a variety of uses. You have the ability to filter results, view a list or a tree, arrange which filters to apply in which order. It’s a very interactive tool. There are a lot of tools and figuring out which tool does what you need is a challenge, we want to make it easier. It’s a read only website, feel free to push buttons and see what it can do. If something breaks, let us know! | ||
|
||
## Who can update this? | ||
Anyone can contribute to this. It’s open source! You can see all the details in our GitHub repo | ||
https://github.com/ossf/sbom-everywhere | ||
|
||
## What sort of information can we add? | ||
We are trying to capture and track as much information about the SBOM ecosystem we can. Meetings, projects, tools, formats, standards, everything. If you’re unsure, let’s chat about it, you can find our details here https://sbom-catalog.openssf.org/about-us.html | ||
|
||
## How can I add an entry or fix an error to the Catalog or Wiki? | ||
Open an issue in GitHub https://github.com/ossf/sbom-everywhere/issues | ||
We’re working on a nice contributing guide, but the issue is easiest right now. The guide is still a few weeks out probably. | ||
|
||
## Is the catalog only for open-source projects? | ||
We accept all tools, not only open-source tools. Feel free to open an issue if you’re unsure. We’re happy to discuss anything. | ||
|
||
## What’s the license? | ||
Contributions to the SBOM Catalog and Wiki should be considered under the Apache 2.0 open source license |