GitBOM
gitbom.dev
gitbom.dev
Edit: Someone in a different comment said those cases are grandfathered because they named themselves before Git was trademarked
Cool...so exclusive. /s
Alternatively, you could name your project $FOO and host your Git service on `git.$FOO.tld`.
It's likely that these standards will start to "trickle down" from US Federal Government to other levels of US government and across general contract negotiations for software deliveries.
Has anyone started delivering SBOMs as part of their delivery? We've had to deliver reproducible build infrastructure and source as part of contractual escrow conditions, but there's a big difference between "reproducible" and actually byte-for-byte equality to a released SBOM.
https://www.reproducible-builds.org/ https://tests.reproducible-builds.org/debian/reproducible.ht...
Any other distro can be treated similarly really.
Not everything is going to be accepted as part of Debian as a distribution.
For situations where one is using Debian but also software not in Debian, you can create an internal apt repository and make internal .deb packages to put in the internal apt repository.
Not sure about the "Git" trademark part...
but fully capitalizing on git branding (in a way that violates the git trademark rules) to try look "official", even including using the logo. Icky.
This project on the other hand straight up rips off the Git logo. It makes this project look official. If I wasn't paying attention I could easily have been fooled.
The idea of using a directed acyclic graph, along with content addressable artifacts (or representation of external artifacts) could potentially work well alongside spdx and other standards for identifying packages and dependencies at a higher level of abstraction.
Delivering a git repo as your SBOM has distinct advantages in terms of tooling and reproducability, and general "gitops"/git flow processes accomodate multiple releases and signed tags to provide roots of trust for SBOMs.