-
Notifications
You must be signed in to change notification settings - Fork 436
Open
Labels
Description
Binaries built using Go 1.18+ have extra info embedded, e.g., for ko itself:
build -compiler=gc
build CGO_ENABLED=0
build CGO_CFLAGS=
build CGO_CPPFLAGS=
build CGO_CXXFLAGS=
build CGO_LDFLAGS=
build GOARCH=amd64
build GOOS=darwin
build GOAMD64=v1
build vcs=git
build vcs.revision=895cff9823bdde4341ebd3b1893307a42d12e1f4
build vcs.time=2022-03-28T13:55:53Z
build vcs.modified=true
We should collect this and put it into SPDX and CycloneDX SBOMs.
Reactions are currently unavailable