The purpose of this issue is to provide SBOMs for all ASF binary distributions, starting with those that:
- contain executable applications,
- bundle all or most of their dependencies.
These are IMHO the most critical distributions, since users can not easily upgrade vulnerable dependencies without a new release.
The following table contains a list of binary application distributions of various Apache TLPs.
Currently only 10% of the TLPs are included:
The purpose of this issue is to provide SBOMs for all ASF binary distributions, starting with those that:
These are IMHO the most critical distributions, since users can not easily upgrade vulnerable dependencies without a new release.
The following table contains a list of binary application distributions of various Apache TLPs.
Currently only 10% of the TLPs are included: