LV EVB-4.7 — Software Bill of Materials
REQ-EVB-4.7-SBOM
Proof level: TECHNICAL POC
Demonstrates
- ✓ SPDX SBOM generated per build via Trivy (the tender's own mandated CVE scanner, reused rather than adding a second tool) — verified against the real production image (170 packages catalogued, valid SPDX-2.3); CVE gate (scripts/scan/run.sh) verified clean (0 CRITICAL) against the same image
Pending external information
- ○ LV cites SBOM only as a documentation sub-bullet under LV 1.1.6, not under an item literally numbered EVB-4.7 — exact source of the "4.7" numbering unconfirmed, see docs/tender-extracts/leistungsverzeichnis.md discrepancy #8
Technical documentation
docs/security.md