k8-sig's BOM #7170
-
Hi, I wanted to ask about the functionality relationship between ORT and https://github.com/kubernetes-sigs/bom:
Thanks. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Looks like the So bottom line, |
Beta Was this translation helpful? Give feedback.
Looks like the
bom
tool basically accepts two types of input: containers and directories / files. Only if the directory happens to contain a Go module, package-level dependencies are determined. I.e.bom
completely lacks ORT's package-manager support. If the directory is not a Go module, its files are being listed as part of the SPDX BOM.So bottom line,
bom
rather seems to complement ORT than offering the same functionality, and eventuallybom
could be used to implement #1833.