Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Despite CycloneDX being described as one of the default SBOM formats, when publishing, we pick the first one (which is
spdx
by default) and publish that only.apko/pkg/build/oci/sbom.go
Lines 153 to 157 in 4f9a4c6
As a result, this code path is effectively never used (by Chainguard, at least), and since there are no tests or validation we have no idea whether this works or will continue to. Instead of having effectively dead code, let's just remove it.
TF-apko already only supports SPDX (ref)