Skip to content

Enhancement: Use SBOM generated by Cargo #192

@SDAChess

Description

@SDAChess

Hello,

With the merge of the Cargo SBOM into Cargo Nightly (rust-lang/cargo@7ea222d), it would be a valuable addition to the cargo-auditable code to ingest the dependencies from the generated SBOM.

It would probably solve a lot of common issues related to cargo metadata command.

I think cargo-auditable is still very relevant in generating the SBOMs from tools like syft when using containers that have their own dependencies and would love to see this work in cargo-auditable.

let me know if there is anything I could do to help this effort, if you need help with contributions especially.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions