Back to Eclipse Foundation
GSoC 2026

Supporting SBOM as Input

This project aims to extend the functionality of the Eclipse Dash License Tool by adding support for Software Bill of Materials (SBOM) files as input, specifically in CycloneDX and SPDX formats. Currently, the tool can accept and process dependencies from Maven files or NPM package files, but lacks the capability to accept SBOM files as input - a feature that is becoming more standardized in modern licensing software. This proposed solution involves the implementation of specific file parsers for CycloneDX and SPDX formats, extracting and normalizing component data, and then integrating this data into the tool's existing workflow. In addition, this project will support the generation of enriched SBOM outputs that include updated licensing information whilst preserving the initial contents of the file structure and metadata. The final deliverables for this project include SBOM input support via new command-line arguments, file parsing, integration with the rest of the tool's existing workflow, enriched SBOM output generation, extensive testing, and explicit documentation.

Project details

Contributor

DominicCristello

Mentors

Not available

Technologies

Not listed in the archive