-
Notifications
You must be signed in to change notification settings - Fork 55
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Propagating CycloneDx information #1453
Propagating CycloneDx information #1453
Conversation
1d6b3b6
to
cc5b4f5
Compare
Datadog ReportBranch report: ✅ 0 Failed, 152 Passed, 0 Skipped, 1m 14.97s Total duration (2m 18.86s time saved) |
92b99ea
to
dcb0ab8
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should probably make sure we align on https://github.com/DataDog/dd-source/pull/129608 before landing.
What and why?
The goal of this PR is to proagate new information coming from CycloneDX sboms, such as libraries package manager, is a library direct or not, files and dependencies between components.
How?
This is done by updating the CycloneDX SBOM to SCARequest payload. Please note it will be more convenient to review it commit by commit as they have been split by propagation type + 1 refacto at first to prepare file propagation
Review checklist