Server SBOM rebuild to master/v8.x/v7.0

XMLWordPrintableJSON

    • Type: Improvement
    • Resolution: Unresolved
    • Priority: Minor - P4
    • 8.3.0-rc0
    • Affects Version/s: None
    • Component/s: None
    • 5
    • 🟢 On Track
    • 3
    • TBD
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      The Server SBOM (10gen/mongo/sbom.json), while diligently maintained manually by the Server team, lacks accuracy and depth in some areas.

      R&D Security will rebuild the SBOM to better meet NITA Minimum Elements for Software Bill of Materials, OWASP Software Component Verification Standard (SCVS) Level 1, as well as include the necessary component identifiers for vulnerability discovery and VEX responses.

      This is in support of efforts to automate the SBOM generation (RNDSEC-1151).

              Assignee:
              Jason Hills
              Reporter:
              Jason Hills
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: