So I heard you like , so I put SBOM into the wheels in RPMs, so when you unwheel the wheels, you get the SBOM.

If your Python virtual environment was created on Fedora, your scanner can recognize fixes in patched pip (or setuptolos) within.

The question, however, is: What to do with this now :D

developers.redhat.com/articles

Anyway, security scanner people, please reach out.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://floss.social/users/hroncok/statuses/115735961074998764 on your instance and quote it. (Note that quoting is not supported in Mastodon.)