Welcome to sbom-vm Discussions! #8
popey
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Welcome to sbom-vm Discussions!
👋 Hello SBOM enthusiasts!
Welcome to the official discussions area for sbom-vm, a tool that generates Software Bills of Materials (SBOMs) from virtual machine disk images without booting the VM!
🔍 What is sbom-vm?
sbom-vm bridges a critical gap in the SBOM ecosystem by leveraging common Linux utilities to mount VM disk images in read-only mode and generate SBOMs using Syft. This is particularly useful when dealing with large filesystems where running Syft directly inside the VM might cause resource exhaustion.
💡 How to use this space
We've created this discussions area to:
🚀 Get started
🔮 What's next for sbom-vm?
The current implementation is a prototype that demonstrates the concept of generating SBOMs from VM disk images without booting them. Our goal is to potentially incorporate these capabilities directly into Syft or Stereoscope.
We'd love to hear your thoughts on:
🤝 Contributing
Contributions are welcome! Feel free to submit Pull Requests or open issues to discuss major changes. Whether you're a security professional, VM expert, or just interested in SBOMs, we'd love to have you join the community.
Happy scanning! 📊
Beta Was this translation helpful? Give feedback.
All reactions