Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SBOM Report for Infor( GRC product) #7309

Closed
AdityaBhinge opened this issue Jul 16, 2024 · 3 comments
Closed

SBOM Report for Infor( GRC product) #7309

AdityaBhinge opened this issue Jul 16, 2024 · 3 comments
Labels

Comments

@AdityaBhinge
Copy link

Hi,

Aditya here from the Infor GRC automation team. We have been using these packages for our product, GRC (Governance Risk and Compliance), for a while now. Infor GRC has been generating SBOM reports for vulnerability scanning. Recently, we have been asked to obtain SBOM reports from third-party resources we have been using. Therefore, I request you to provide me with the SBOM reports for the packages mentioned below, along with their versions. The reports are required for these versions only and in CycloneDX JSON format.

guava - 32.1.1-jre
failureaccess - 1.0.1
j2objc-annotations -2.8
proto-google-common-protos -2.7.4
protobuf-java -3.21.12
jimfs -jimfs

@chaoren
Copy link
Member

chaoren commented Jul 31, 2024

we have been asked to obtain SBOM reports from third-party resources we have been using

I request you to provide me with the SBOM reports for the packages mentioned below

That's your job. You can look at the pom.xml files for the dependency versions of each project. We're not going to spend time doing your job for you.

The reports are required for these versions only and in CycloneDX JSON format.

We certainly don't require them. You require them. Please generate them yourself.

@chaoren chaoren closed this as completed Jul 31, 2024
@chaoren chaoren added invalid invalid requests status=invalid labels Jul 31, 2024
@ben-manes
Copy link
Contributor

GitHub generates it fwiw

https://github.com/google/guava/network/dependencies

@chaoren
Copy link
Member

chaoren commented Aug 2, 2024

Interesting. Thanks @ben-manes. There's even an Export SBOM button. @AdityaBhinge does that produce what you need?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants