We should investigate adding Software Bill of Materials (SBOM) scanning for the container images referenced by modules. The investigation should identify a suitable scanner and determine how its results could fit into repository review or CI workflows.
We should investigate adding Software Bill of Materials (SBOM) scanning for the container images referenced by modules. The investigation should identify a suitable scanner and determine how its results could fit into repository review or CI workflows.