Open source projects could sell SBOM fragments
11–20 of 64 posts
Re: Open source projects could sell SBOM fragments
#12This doesn't make much sense to me. Why would someone want to pay each and every open source project to see the SBoM when they could pay a single provider or use an open source tool to get that info for all of their dependencies?
Re: Open source projects could sell SBOM fragments
#13Re: Open source projects could sell SBOM fragments
#14Re: Open source projects could sell SBOM fragments
#15Re: Open source projects could sell SBOM fragments
#16This doesn't make much sense to me. Why would someone want to pay each and every open source project to see the SBoM when they could pay a single provider or use an open source tool to get that info for all of their dependencies?
For private usage no one gives a shit about SBOM, but for enterprise usage it's absolutely required.
Re: Open source projects could sell SBOM fragments
#17This doesn't make much sense to me. Why would someone want to pay each and every open source project to see the SBoM when they could pay a single provider or use an open source tool to get that info for all of their dependencies?
Right. A significant part of the reason open source wins so handily isn't that the money for a proprietary solution is always more than it's worth, it's that you can just pull open source dependencies without going through purchasing.
Re: Open source projects could sell SBOM fragments
#18it could never work with corporate using micro transactions like that
Re: Open source projects could sell SBOM fragments
#19In GNU Guix declaring the license(s) of a package is mandatory so it kinda automates the process of creating SBoM.
Re: Open source projects could sell SBOM fragments
#20Or, flip the script, if you're concerned enough about supply chain security to mandate an SBOM, you probably don't trust the supplier anyway.
There's the "but I signed it" crowd, but the wheels fall off when they've signed compromised artifacts too.
I just don't see a scenario where an SBOM that cannot be inspected and verified would be useful. If you have the infrastructure to do it, you're generating SBOMs anyway.