Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
exporter: ensure spdx order prioritizes primary sbom
If we have any SBOMs that are notated as primary, then we should ensure that they appear before the others in the list of attestations. This ensures that clients should be able to naively take the "first" SBOM, to get the most relevant one that applies to the main rootfs. Signed-off-by: Justin Chadwell <[email protected]>
- Loading branch information