Draft Proposal: Artifact Dependency Graph (ADG) Generation for Python Wheels

I believe the SBOMS for Python packages proposal by @sethmlarson is an existing, standards compliant (supports spdx), and more developed proposal to address software supply chain data in python packages:

In addition the proposal posted here is limited in that it is framed around setuptools not as a general mechanism for all build backends.

6 Likes