Skip to content
Snippets Groups Projects
  1. Jan 07, 2024
    • Sheogorath's avatar
      82262222
    • Sheogorath's avatar
      removal(sbom-operator): Drop sbom-operator · 77f29c1c
      Sheogorath authored
      After running it for a while now, it turns to be not too useful for the
      SI Infra. The main use-cases for SBOMs at this point are security scans
      and license compliance.
      
      None of these are use-cases that I actually used the produced SBOMs for.
      
      One of the main issues for using these SBOMs for security scans was the
      glaring false-negatives for actual security issues due to a lack of
      detection of certain packages/application within containers.
      
      Instead running renovate and regularly upgrading all parts has proven
      way more practical.
      
      License Compliance, while might being a potential concern, is not on the
      list of things to worry about right now.
      
      Finally another issue with this particular operator, was it breaking for
      various reasons and resulting in dropping out regularly, which made
      SBOMs also out of date.
      77f29c1c
  2. Jan 06, 2024
  3. Jan 04, 2024
  4. Jan 02, 2024
  5. Jan 01, 2024
  6. Dec 31, 2023
Loading