-
Type:
Bug
-
Resolution: Won't Fix
-
Priority:
Major - P3
-
None
-
Affects Version/s: None
-
Component/s: None
-
None
-
Server Security
-
ALL
-
Server Security 2025-05-09
-
None
-
3
-
TBD
-
None
-
None
-
None
-
None
-
None
-
None
When developers update/add a new third party package and follow the README inside src/third_party they are instructed to update the sbom.json.
There is no instruction to update README.third_party.md by running the script in the top comment of this file, making the file become outdated.
We should either:
- Remove README.third_party.md
- Update src/third_party/README.md to let developers know they need to run the script after updating the sbom and add a test that fails if README.third_party.md does not match sbom.json.