Skip to content

Infer repositories from SBOM #5

@ribbybibby

Description

@ribbybibby

In some cases we can figure out the repository for a package just by looking at the SBOM, without the deps.dev dataset.

For instance:

This would be useful when the package isn't in deps.dev but its repository is in the scorecard dataset. Or, when the package is internal.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions