Update vulnetix_cli.json - #121
Conversation
We've extended features to cover gitlab, PQC, and AI inventory Signed-off-by: Stof <93355168+0x73746F66@users.noreply.github.com>
jkowalleck
left a comment
There was a problem hiding this comment.
Thank you for the update.
I have some remarks.
| "ANALYSIS", | ||
| "TRANSFORM" | ||
| "TRANSFORM", | ||
| "AUTHOR" |
There was a problem hiding this comment.
AUTOR seams not right for an automated tool.
https://cyclonedx.github.io/tool-center/tool.html#tool_functions
AUTHOR - Tools that human authors can use to create CycloneDX BOMs.
| "AUTHOR" |
There was a problem hiding this comment.
it has go module architecture where the authoring primitive are used by any go.mod project
There was a problem hiding this comment.
a programmable interface does not mean author capabilities. please remove that property.
There was a problem hiding this comment.
you mean cli, sure, that was always there https://docs.cli.vulnetix.com/docs/cli-reference/cdx/
I thought you were asking that the cli authoring was not some low level variation like sdk/lib but you can see the cli bom auhoing is there for sbom, cbom, ai-bom specs.
Maybe instead of saying "remove" on repeat, ask some clarifying questions next time? I was the contirbutor of the pubisher spec for TEA, I kind of am pretty meticulous about this stuff. Cheers
There was a problem hiding this comment.
Look, your product describes as a
A vulnerability scanner [...]
A scanner clearly has no authoring capabilities.
Authoring does not mean create by a machine, but is a manual process done by humans by hand.
Like Writing an BOM in an editor or using some UI to drag/drop/click the thing by hand.
Providing an API is not authoring capability.
Writing a program with a library is not authoring.
Using an API is not considered authoring.
AUTHOR - Tools that human authors can use to create CycloneDX BOMs.
please remove this predicate.
There was a problem hiding this comment.
I'm being as polite as possible here... the ignorance of facts is starting to irk. want to get an opinion in the owasp members area? I'd be happy for someone else to compare authoring of existing tools like cdxgen and purge them all on your criteria - then I'll remove it from mine in accordance to such a rigid criteria if it's fair and applied to all tools equally
There was a problem hiding this comment.
I'd be happy for someone else to compare authoring of existing tools like cdxgen and purge them all on your criteria - then I'll remove it
What do you mean?
Authoring was removed as a false claim on ~150 tools already, as none of them had any indication for authoring to the current criteria. Neither does your tool.
I'd just remove the wrong claim and have the rest merged, then.
There was a problem hiding this comment.
I'll remove the author code from this tool too then, make users Install 2 tools for CycloneDX tasks. thanks, I'll plan that chamge
There was a problem hiding this comment.
unintended changes.
please move them to a dedicated pullrequest.
There was a problem hiding this comment.
unintended changes.
please move them to a dedicated pullrequest.
We've extended features to cover gitlab, PQC, and AI inventory
AI-BOM
CBOM
Gitlab
CycloneDX VEX creation during SCA Autofix
CycloneDX VEX creation during SCA reachability