Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

I'd like a document table #695

bobmcwhirter started this conversation in General
Discussion options

Currently, there's parallelism between advisory and sbom in terms of labels, hashes, etc.

Looking forward, I see a couple of reasons to pull that commonality into a document table.

  1. avoid any skew between hashes we keep for one type of document vs another.
  2. support (future) plans to scrobble SigStore for information about all documents (not caring if they're sboms or advisories or...)
  3. support rows within the SBOM and Advisory table that are not hooked to a specific document. e.g., if someone is using Trustify to author or augment existing data bits, using human-derived and inputted knowledge.
You must be logged in to vote

Replies: 1 comment

Comment options

Ultimately, advisory and sbom could have a nullable document_id column pointing to any source document, iff applicable.

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
1 participant

AltStyle によって変換されたページ (->オリジナル) /