Skip to content

Create SBOMs for ASF application binary distributions #35

@ppkarwasz

Description

@ppkarwasz

The purpose of this issue is to provide SBOMs for all ASF binary distributions, starting with those that:

  • contain executable applications,
  • bundle all or most of their dependencies.

These are IMHO the most critical distributions, since users can not easily upgrade vulnerable dependencies without a new release.

The following table contains a list of binary application distributions of various Apache TLPs.
Currently only 10% of the TLPs are included:

Application Download URL Tool SBOM
Accumulo https://accumulo.apache.org/downloads/ Maven Assembly [ ]
ActiveMQ Artemis https://activemq.apache.org/components/artemis/download/ Maven Assembly [ ]
ActiveMQ Classic https://activemq.apache.org/components/classic/download/ Maven Assembly [ ]
Age only source releases? [ ]
Airavata https://airavata.apache.org/development.html#downloads Maven Assembly [ ]
Airflow only Python packages + Docker? Python [x]
Allura only source releases? [ ]
Ambari only source releases? [ ]
Ant https://ant.apache.org/bindownload.cgi Ant [ ]
APISIX only source releases + Docker [ ]
Aries only sample applications [ ]
Arrow only libraries [ ]
AsterixDB https://asterixdb.apache.org/download.html Maven Assembly [ ]
Atlas only libraries? [ ]
Avro only libraries? [ ]
Axis https://axis.apache.org/axis2/java/core/download.html Maven WAR [ ]
Beam only libraries? [ ]
Bigtop https://bigtop.apache.org/download.html#releases Dpkg and Rpm [ ]
Bookkeeper https://bookkeeper.apache.org/releases/ Maven Assembly [ ]
Brooklyn https://brooklyn.apache.org/download/index.html Maven Assembly [ ]

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions