Skip to content

Conversation

@onelapahead
Copy link

Without a lockfile - we can scan the distributed JARs with tools like trivy within Docker images, but it struggles to generate an SBOM.

This makes it significantly simpler and helps lock deps in accordance with the gradle/verification-metadata.xml file.

…ation

Signed-off-by: hfuss <hayden.fuss@kaleido.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants