Skip to content

SBOM for mainframe applications Working Group #848

@suman-gopinath

Description

@suman-gopinath

Describe the purpose of the group in no more that 4-5 sentences

To refine and adapt industry standard SBOMs to cater to traditional z/OS applications primarily - COBOL, PL/I, HLASM and mixed language applications. The scope of this charter will target creation of SBOMs for z/OS applications and Application products delivered by Vendors i.e. code that is invoked during runtime of a z/OS Application

Goals of the working group

  1. Review existing industry standard SBOM definitions and formats (including SPDX implementation at Telco)
  2. Work with SPDX and CycloneDX to identify attributes and fields pertaining to z/OS Applications. Work with the communities to add them to the appropriate profiles. .
  3. Identify SBOM attributes and specifications for Build and Deploy of traditional z/OS applications that follow an incremental build and deploy processes – with the ability to extend to full application builds and deploy for packaged application products
  4. Validate and review identified standards across at least 10 different mainframe enterprises

Non-goals of the working group

  1. This workgroup will only define the formats and if necessary, validation libraries for the formats. It will not include tooling to create SBOMs
  2. Prioritization of individual SBOM delivery timelines across vendors
  3. SBOMs for pure-java, python, NodeJS applications running on z/OS. There exists tooling frameworks and libraries for these technologies. This workgroup will align and ensure consistency across applications

Deliverables

  1. Published Github pages with
  2. Introduction to SBOMs for z/OS applications
  3. Guidelines on generating SBOMs from build and deploy
  4. Identified attributes as necessary for z/OS applications
  5. Packages for validating SBOMs

Metadata

Metadata

Labels

2-annual-reviewAnnual Review for a Project or Working Group

Type

No type

Projects

Status

Future Meeting Agenda Items

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions