Skip to content

Add Stage&Context Scan for SBOM #3263

@kpango

Description

@kpango

Describe the issue

The current Docker image lacks meaningful information for the SBOM due to its single-binary distroless image. Therefore, we believe additional analysis should be pursued by adding SBOM options (BUILDKIT_SBOM_SCAN_CONTEXT, BUILDKIT_SBOM_SCAN_STAGE).

  • Vald Version: v1.7.17
  • Go Version: v1.24.5
  • Rust Version: v1.88.0
  • Docker Version: v28.3.2
  • Kubernetes Version: v1.33.3
  • Helm Version: v3.18.4
  • NGT Version: v2.4.3
  • Faiss Version: v1.11.0

Metadata

Metadata

Assignees

No one assigned

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions