Every tool that makes automated decisions about dependencies has invented its own policy format. After surveying ~40 tools (cargo-deny, Snyk, Trivy, Grype, OSV-Scanner, LicenseFinder, and more), the author finds a chaotic landscape spanning TOML, YAML in ten different schemas, XML, JSON, Rego, Kotlin scripts, and proprietary

9m read timeFrom nesbitt.io
Post cover image
Table of contents
License policy #Vulnerability policy #Package bans #The full inventory #OPA #Existing standards #What a standard might cover #Relationship to SBOMs #

Sort: