Skip to content

k8-sig's BOM #7170

Answered by sschuberth
dgutson asked this question in Q&A
Jun 21, 2023 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

Looks like the bom tool basically accepts two types of input: containers and directories / files. Only if the directory happens to contain a Go module, package-level dependencies are determined. I.e. bom completely lacks ORT's package-manager support. If the directory is not a Go module, its files are being listed as part of the SPDX BOM.

So bottom line, bom rather seems to complement ORT than offering the same functionality, and eventually bom could be used to implement #1833.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@dgutson
Comment options

Answer selected by dgutson
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants