Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Tool name: openchain-telco-sbom-validator #19

Open
4 of 60 tasks
vargenau opened this issue Jan 22, 2025 · 4 comments
Open
4 of 60 tasks

Tool name: openchain-telco-sbom-validator #19

vargenau opened this issue Jan 22, 2025 · 4 comments

Comments

@vargenau
Copy link

vargenau commented Jan 22, 2025

homepage_url

https://pypi.org/project/openchain-telco-sbom-validator/

contact_email

gergely.csatari@nokia.com

code_view_url

https://github.com/OpenChain-Project/Telco-WG/tree/main/tools/openchain_telco_sbom_validator

spdx_license_expression

Apache-2.0

description

A script to validate SBOMs against version 1.0 of the OpenChain Telco SBOM Guide.

primary_languages

Python

short_term_roadmap

Add possibility to recursively validate linked SBOMs.

long_term_roadmap

Update tool for later releases of the OpenChain Telco SBOM Guide.

proprietary_data

  • Yes, the tool depends on proprietary data sources

commercial_features

  • Yes, the tool has a commercial version with different/additional features

capabilities

  • Identifiers - Use Package-URL (PURL) identifiers
  • Identifiers - Use SPDX license expressions
  • Scanning - Analyze package manifests and lockfiles
  • Scanning - Analyze package files
  • Scanning - Scan for copyright
  • Scanning - Scan for license
  • Scanning - Analyze source code
  • Scanning - Analyze containers
  • Scanning - Analyze installed system packages (linux distros)
  • Scanning - Analyze installed application packages
  • Scanning - Other analysis
  • Packages - Inventory packages
  • Packages - Inventory packages dependencies
  • Packages - Resolve dependencies
  • Packages - Navigate or display dependency graph
  • Compliance - Generate CycloneDX SBOMs
  • Compliance - Generate SPDX SBOMs
  • Compliance - Validate CycloneDX SBOM
  • Compliance - Validate SPDX SBOMs
  • Compliance - Generate CycloneDX VEX
  • Compliance - Generate CSAF VEX
  • Compliance - Generate OpenVex
  • Compliance - Generate other compliance documents
  • Policies - Define and check license policies
  • Policies - Define and check security policies
  • Policies - Define and check other policies
  • Data - Database of Package metadata
  • Data - Database of Package dependency relationships
  • Data - Database of License obligations
  • Data - Database of Licenses
  • Data - Database of Vulnerabilities
  • License - Help triage license issues
  • License - Generate license credit and attribution notices
  • License - Generate source code redistribution lists
  • Vulnerabilities - Detect vulnerable code in packages
  • Vulnerabilities - Find known vulnerabilities for package
  • Vulnerabilities - Determine reachable vulnerabilities
  • Vulnerabilities - Help triage vulnerabilities
  • Binaries - Analyze binaries
  • Binaries - Analyze ELF binaries
  • Binaries - Analyze Windows binaries
  • Binaries - Analyze firmware binaries
  • Binaries - Analyze Other binaries
  • Matching - Match source code
  • Matching - Match binary code
  • Tracing - Trace code execution
  • Tracing - Trace build
  • Code Security - Analyze code statically (SAST/linting)
  • Code Security - Analyze code dynamically (DAST)
  • Download - Source package
  • Download - Source repositories
  • Download - Binary package
  • Deployment - Deployable as containers (Docker/OCI/k8s/etc)
  • Deployment - Deployable in CI/CD pipelines
  • Deployment - Deployable as a library
  • Run - Run as a command line tool
  • Run - Run as a web application
  • Run - Run as an API service

other_capabilities

No response

@pombredanne
Copy link
Member

@vargenau You are first!
Should we add a new "Validate SBOM" capability? Would it be different for SPDX and CycloneDX?

@pombredanne
Copy link
Member

I am adding it

pombredanne added a commit that referenced this issue Jan 22, 2025
Reference: #19
Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>
@pombredanne
Copy link
Member

@vargenau please check any of the new "SBOM validation" boxes that matter for your tool!

@vargenau
Copy link
Author

vargenau commented Mar 5, 2025

I have checked more boxes.

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants