← Back to issue list

Auto generate an SBOM?

View original Github issue

Metadata

Project
charmcraft
Number
#1013
Type
issue
State
closed
Author
sed-i
Labels
Created
Updated
Closed

Current evaluation

Closed as superseded. The request was deferred to a separate, ongoing initiative focused on SBOM generation, making this proposal redundant.

Suggested action:

No scores available.

Issue body

There is a potential threat from pip packages vendored at `pack` time. Would it make sense, to ease the scanning effort, to auto-generate an SBOM? On the other hand, `*.charm` could be manually modified between pack and upload, so perhaps it's a charmhub concern?

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Closed as superseded. The request was deferred to a separate, ongoing initiative focused on SBOM generation, making this proposal redundant.
qwen3.6-35b-a3b-mtp-q6
Staleness: 95
Complexity: 45
Confidence: 85
Support Request: 15
close stale Suggestion to auto-generate a Software Bill of Materials (SBOM) for vendored pip packages during the pack process. The issue remains open with no maintainer engagement or comments after over three years.
qwen3.6-35b-a3b-mtp-q6
Staleness: 95
Complexity: 20
Confidence: 85
Support Request: 10
close stale Suggests auto-generating a software bill of materials (SBOM) to track vendored pip packages during pack time. No maintainer response or activity since creation.
qwen3.6-35b-a3b-mtp-q6
Staleness: 95
Complexity: 20
Confidence: 55
Support Request: 10
needs triage Proposes auto-generating an SBOM for vendored pip packages to streamline security scanning, noting manual .charm edits may shift responsibility to charmhub. Unlabeled, inactive for over three years, zero comments. Awaiting triage and assignment.

Update history

Date Change
closed

Related issues

No related issues found above the similarity threshold.