Uploaded image for project: 'MariaDB MaxScale'
  1. MariaDB MaxScale
  2. MXS-5611

Update MaxScale SBOM Format to .cdx.json for Vulnerability Scanning Compatibility

    XMLWordPrintable

Details

    • Task
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • None
    • N/A
    • build
    • None

    Description

      The current file format for the SBOM files for MaxScale are provided only in .tgz format which are not compatible for automated security tooling.
      Issue:

      • The Security team’s vulnerability scanning tools are configured to locate SBOMs using the pattern:

        {product}/**/{version}/**/*.cdx.json
        

      • .tgz-formatted SBOMs are not recognized or scanned, which creates a gap in automated security coverage.

      MaxScale SBOMs should be made available in the .cdx.json format, similar to how it is published for MariaDB Enterprise Server.

      Attachments

        Activity

          People

            tturenko Timofey Turenko
            mdeweerd Michael Deweerd
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.