Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

idea: compute the SBOM for a deployed contract on chain #30

Open
monperrus opened this issue Jan 8, 2025 · 2 comments
Open

idea: compute the SBOM for a deployed contract on chain #30

monperrus opened this issue Jan 8, 2025 · 2 comments

Comments

@monperrus
Copy link
Contributor

idea for a feature in SCSC: compute the SBOM for a deployed contract on chain

useful for transparency and compliance

ever seen that?

@monperrus
Copy link
Contributor Author

cool concept and name
cbom: contract bill of materials

@mokita-j
Copy link
Contributor

mokita-j commented Jan 8, 2025

love it, components for CBOM
Dependeny info: dependency graph of the contracts depends on + libraries the source code uses and their suppliers (e.g. OpenZeppelin)
Build info: Compiler version + optimization config, source code availability, standards that it follows (e.g. ERC-20)
Timestamps: block height of deployment
Security: known vulnerabilities (CVE)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants