Skip to content
Discussion options

You must be logged in to vote

all dependencies are resolved by downstream users. Your SBOM would not reflect the things downstream users would see on their system, right

As it stands, correct. But once bctl starts pegging the dependencies to specific version, then it no longer would be the case.

even if all dependencies are pinned to exact versions, the dependency resolution is still done downstream. you have NO control what downstream users actually install and where it comes from.

For example, when people used Conda for the ecosystem management, modified dependencis are pulled from condaforge and would still match you runtime-requirements.
Or when your package is vendored by linux distros, the actual dependencie…

Replies: 1 comment 8 replies

Comment options

You must be logged in to vote
8 replies
@jkowalleck
Comment options

@jkowalleck
Comment options

@laur89
Comment options

@jkowalleck
Comment options

Answer selected by jkowalleck
@jkowalleck
Comment options

@laur89
Comment options

@jkowalleck
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants