You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Today the SBOM cataloger is on by default and has no configurability to select/deselect SBOMs in certain paths, include/exclude items within SBOMs conditionally, or be able to enrich the package and relationships found in a flexible way. We could consider making the SBOM cataloger opt-in for now until we discover better mechanisms here. This could mean something like this to enable the SBOM cataloger:
syft <my-image> --include-sboms
There are several options forward here --interested in hearing thoughts here.
The text was updated successfully, but these errors were encountered:
Developer note: Since the builder PR landed, the change fairly simple, I think: updating the SBOM cataloger line to remove the pkgcataloging.ImageTag, pkgcataloging.DeclaredTag, pkgcataloging.DirectoryTag, pkgcataloging.ImageTag, (leaving only "sbom"). Those tags are used to select default catalogers for image and directory scans. But now the user can just re-enable this using the selection configuration, like syft --select-catalogers +sbom-cataloger
Today the SBOM cataloger is on by default and has no configurability to select/deselect SBOMs in certain paths, include/exclude items within SBOMs conditionally, or be able to enrich the package and relationships found in a flexible way. We could consider making the SBOM cataloger opt-in for now until we discover better mechanisms here. This could mean something like this to enable the SBOM cataloger:
There are several options forward here --interested in hearing thoughts here.
The text was updated successfully, but these errors were encountered: