Skip to content

Why not utilize the existing KBOM? #4738

Answered by itaysk
y4ney asked this question in Q&A
Jun 30, 2023 · 2 comments · 2 replies
Discussion options

You must be logged in to vote

Hi, Trivy has many capabilities and there are alternative tools you can choose. For example, when we added SBOM support in Trivy, the Syft tool was already available and offered this functionality, yet we wanted to provide this feature natively to Trivy users.

About kbom - when we started to work on this feature, KSOC's kbom tool didn't exist, and when they launched it was exclusive to their own format, while we thought kbom should be in CycloneDX. Nevertheless we reached out to KSOC team and offered to collaborate but for different reasons it didn't happen. On the flip side, it's good that users have more options to choose from. Our goal is to make Trivy the best oss tool for cloud nativ…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by y4ney
Comment options

You must be logged in to vote
2 replies
@itaysk
Comment options

@y4ney
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question.
2 participants