Re: SBOM Tool for OpenWRT to feed Dependency Track

2023-10-26 Thread Petr Štetiar
Pfendtner Steffen [2022-10-18 14:38:56]: Hi, > We decided to publish our internal fork of the Timesys SBOM Tool we found on > github. You find our version at: https://github.com/ads-tec/sbom-openwrt thanks for sharing! BTW I took that output and drafted first version[1] by extending current im

Re: SBOM Tool for OpenWRT to feed Dependency Track

2022-10-24 Thread Dave Taht
This work (cleaning up SBOM, clearly identifying CVEs, getting on top of more) sounds like an *ideal* candidate for funding under the NLNET entrust fund: https://nlnet.nl/entrust/ Applications are easy, the amount available per project usually in the range of 30-50k eu, and usually approval is ve

Re: SBOM Tool for OpenWRT to feed Dependency Track

2022-10-24 Thread Hauke Mehrtens
On 10/18/22 16:38, Pfendtner Steffen wrote: Hi, We decided to publish our internal fork of the Timesys SBOM Tool we found on github. You find our version at: https://github.com/ads-tec/sbom-openwrt It takes a complete OpenWRT build tree as input and will generate a SBOM in CycloneDX JSON Format

SBOM Tool for OpenWRT to feed Dependency Track

2022-10-18 Thread Pfendtner Steffen
Hi, We decided to publish our internal fork of the Timesys SBOM Tool we found on github. You find our version at: https://github.com/ads-tec/sbom-openwrt It takes a complete OpenWRT build tree as input and will generate a SBOM in CycloneDX JSON Format for the currently configured image. This SBOM