Replies: 2 comments
-
|
Note - renamed this discussion for clarity. |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
That's interesting - there's an obligation to report incidents affecting the build system to ENISA. That implies that you have control over it and likely the way for that is to have an SBOM. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
The creation of a PDE includes a supply chain, which typically contains many elements. In the case of software-based (or "software-heavy") PDEs, many of these elements are themselves software: SBOM builders, build systems, IDEs, dependency/license-checkers, static analysis tools, fuzzers, etc.
Beta Was this translation helpful? Give feedback.
All reactions