You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Eclipse Foundation Security Team is leading an ongoing initiative to support projects in adopting Software Bill of Materials (SBOM), with a particular focus on designing and implementing Github Actions workflows that:
4
-
- automatically generate SBOMs for new project releases, and
5
-
- publish them to our DependencyTrack [instance](https://sbom.eclipse.org)
3
+
The Eclipse Foundation Security Team is leading an ongoing initiative to support projects in adopting Software Bill of Materials (SBOM). Our aim is to enable project in pursuing independent implementations of SBOM generation and upload workflows into their existing release pipelines.
6
4
7
-
As part of this initiative, we are collaborating with early adopter groups to design and implement such workflows tailored to their specific ecosystems and release processes.
5
+
As such, we have been collaborating with Early Adopter projects and offering our hands-on support to design and implement such workflows tailored to their specific ecosystems and release processes. These engagements helped identify common challenges as well as effective solutions, which we are now sharing to accelerate broader adoption.
8
6
9
-
These engagements helped identify common challenges as well as effective solutions, which we are now sharing to accelerate broader adoption. The examples in the table below illustrate a variety of successful implementation strategies developed as a result of these collaborations. They are intended to serve as practical inspiration for projects looking to integrate SBOM generation into their own release workflows.
7
+
The examples in the table below illustrate a variety of successful implementation strategies developed as a result of these collaborations. They are intended to serve as practical inspiration for projects looking to integrate SBOM generation into their own release workflows.
We strongly encourage all projects to take an active role in implementing SBOM in their own release processes. While our initiative provides examples and resources to help projects get started independently, we also maintain a queue of early adopter projects that we are directly supporting. If your project would benefit from our guidance, we welcome you to reach out to the Eclipse Foundation Security Team with the details below.
26
+
We strongly encourage all projects to take an active role in integrating SBOM generation into their release processes. To support this, we provide a comprehensive set of internally developed resources, including detailed documentation, implementation examples, and plug-and-play integrations, enabling projects to adopt SBOM practices independently.
27
+
28
+
Should a project require additional guidance or hands-on assistance, the Eclipse Foundation Security Team is available to provide support. Please feel free to reach out with the following details:
21
29
-**Sent to**: security@eclipse-foundation.org
22
30
-**Subject**: "SBOM Early Adopters"
23
31
-**Project context**:
@@ -27,5 +35,4 @@ We strongly encourage all projects to take an active role in implementing SBOM i
27
35
- Ecosystems
28
36
- Versioning strategy
29
37
- Release process
30
-
31
38
Please note that support availability may depend on current capacity, but we are always happy to engage and assist where possible.
0 commit comments