package_metadata 0.0.13Latest published 1.5mo ago
MODULE.bazel
bazel_dep(name = "package_metadata", version = "0.0.13")
README

Supply-chain rules for Bazel

This repository contains Bazel modules for injecting and collecting supply-chain metadata into builds.

This project is the successor to rules_license.

The intended use cases are:

  • declaring metadata about packages, such as
    • the licenses the package is available under
    • the canonical package name and version
    • copyright information
    • ... and more TBD in the future
  • gathering license declarations into artifacts to ship with code
  • applying organization specific compliance constriants against the set of packages used by a target.
  • producing SBOMs for built artifacts.

[!WARNING] The code here is still in active initial development and will churn a lot.

How to participate

Roadmap

See this page.

Background reading:

These are for learning about the problem space, and our approach to solutions. Concrete specifications will always appear in checked in code rather than documents.

About

No description provided.

@bazel-contrib/supply-chain@bazel-contrib
Homepage
34stars
Thursday, June 25, 2026
@aspect-marvin#9410 package_metadata@0.0.13 (#9410)

Languages

Go4.8%
Python1.1%
Shell0%

Maintainers

@TheGrizzlyDev
@fweikert
@aiuto
@Yannic

Versions

0.0.13 +1.9mo2% 72026-06-25
0.0.10 +5.1mo8% 232026-04-30
0.0.7 +1.2mo30% 852025-11-27
0.0.6 +3.1mo19% 542025-10-23
0.0.5 +11d29% 822025-07-22
0.0.4 +13d0% 12025-07-11
0.0.3 +2.0mo1% 32025-06-27
0.0.2 +1.1mo11% 322025-04-28
0.0.12025-03-26