Skip to content

pip cataloger should support repository url  #680

Open
@sambhav

Description

@sambhav

What would you like to be added:

when pip packages are installed from non default pip indices (pypi), we should store the pip repository url in the sbom

Why is this needed: useful to know the origin of a package

Additional context:

Metadata

Metadata

Assignees

No one assigned

    Labels

    blockedProgress is being stopped by somethingecosystem:pythonrelated to the python ecosystemenhancementNew feature or request

    Type

    No type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions