Skip to content

Lab 4: SBOM Generation & Software Composition Analysis - s.palkina@innopolis.university#459

Open
angel-palkina wants to merge 11 commits intoinno-devops-labs:mainfrom
angel-palkina:feature/lab4
Open

Lab 4: SBOM Generation & Software Composition Analysis - s.palkina@innopolis.university#459
angel-palkina wants to merge 11 commits intoinno-devops-labs:mainfrom
angel-palkina:feature/lab4

Conversation

@angel-palkina
Copy link

Tasks Completed

  • Task 1 — SBOM Generation with Syft and Trivy
  • Task 2 — Software Composition Analysis with Grype and Trivy
  • Task 3 — Comprehensive Toolchain Comparison

Files Changed

  • labs/submission4.md - Complete analysis and findings
  • labs/lab4/ - All generated artifacts:
    • SBOM files (Syft native JSON, Trivy JSON, human-readable tables)
    • Vulnerability scan results (Grype, Trivy)
    • Secrets scanning results
    • License analysis
    • Comparative analysis and accuracy metrics

@angel-palkina angel-palkina changed the title Lab 4: SBOM Generation & Software Composition Analysis Lab 4: SBOM Generation & Software Composition Analysis - s.palkina@innopolis.university Feb 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant