Skip to content

Propositions for enhancements to sbomaudit #5

@gutzbenj

Description

@gutzbenj

Dear @anthonyharrison ,

First of all thanks for creating this beautiful library!

We are currently looking for a way to integrating it into our CI/CD pipeline to check on used libraries.

After giving it a try I noticed there's currently no way to configure the "linting" rules separately e.g. only checking the maxage or only checking the licenses, packages, ...

Would you be open for PRs for

  1. overhauling general stuff e.g. switching to pyproject.toml, uv and ruff for setup and linting
  2. adding a CI/CD pipeline itself
  3. adding tests
  4. enabling smart rule configuration via pyproject.toml / sbomaudit.toml + required opt-in for rules (the most important change for us)
  5. (adapting the output format of the report)

?

Happy weekend!

Sincerely,
Benjamin

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions