You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I know there's -noserial=true, but timestamps are still emitted which prevents the SBOM from being fully reproducible.
Can a flag like -reproducible be added that omits metadata.timestamp from being emitted? Then SBOM will be fully reproducible, and can be checked in CI.