4 ms·
This looks very interesting, there is definitely need for SBOM generators that can handle multiple languages. Do HN got a recommendation for other CLI based SB
by DethNinja 4y ago
This looks very interesting, there is definitely need for SBOM generators that can handle multiple languages.
Do HN got a recommendation for other CLI based SBOM generators?
Dependency Track is too resource intensive for a small scale company, I just need a simple CLI based SBOM generator that can handle C++ (conan), Python and Go.
- astockwell 4y agoThe one I have used is https://github.com/anchore/syft https://github.com/anchore/syft
- deleted 4y ago[deleted]
- pabs3 4y agoDebian is my SBOM.
- klysm 4y ago100% of your deps are Debian packages?
- pabs3 4y agoYep, if they aren't then we add them to Debian. For those who aren't yet Debian members, you can do something similar but publish to your own repo instead.
- wutwutwutwut 4y agoWhat language are you programming in? Just thinking about how this would work if you are using say React.
- pabs3 4y agoLots of different ones, Perl, Python, C, C++ being the main ones. I think there is JavaScript but I don't work on those parts. Looks like node-react is available in Debian now. https://packages.debian.org/sid/node-react https://packages.debian.org/sid/node-react
- wutwutwutwut 4y agoAlright, cool. It's a bit confusing to me to create a dependency from your programming language dependency system to the operating system. But whatever works for you. Wouldn't it be tedious to repackage libraries in Debian format? Why not use cpan or similar directly? Or a local artifact server already supporting existing package formats.
- pabs3 4y agoDependencies across different language ecosystems exist (for eg Python stuff often depends on JavaScript stuff for documentation, or C libraries for faster machine code), it is convenient to encode them all in one package manager format. Repackaging ecosystem libraries is pretty much automated these days but still exposes you to the internals of each library since you need to do QA on everything to get it up to Debian standards first. Once things are in Debian you get an entire community of QA too, checking for new build failures due to changes in other packages, notifying you of new security issues etc. https://wiki.debian.org/AutomaticPackagingTools https://wiki.debian.org/AutomaticPackagingTools