Slide 19
Slide 19 text
19
脆弱性のあるライブラリに変えてから再度SBOM出⼒
Pipfileを修正後、Pipfile.lockを出し直し
pipenv install
SBOMを再出⼒
{
"name": "flask",
"SPDXID": "SPDXRef-Package-1900dc034389c35b",
"versionInfo": "3.0.0",
"supplier": "NOASSERTION",
"downloadLocation": "NONE",
"filesAnalyzed": false,
"licenseConcluded": "NONE",
"licenseDeclared": "NONE",
{
"name": "flask",
"SPDXID": "SPDXRef-Package-2b8b83ad929a375a",
"versionInfo": "2.3.1",
"supplier": "NOASSERTION",
"downloadLocation": "NONE",
"filesAnalyzed": false,
"licenseConcluded": "NONE",
"licenseDeclared": "NONE",
1回⽬ 2回⽬
trivy fs ./ --format spdx-json --output spdx-json-by-trivy.json
出⼒結果