Verification
Provide a detailed description of the proposed feature
The sbom.spdx.json contains dependency information for dependencies managed by brew. We should include dependency information for those not managed by brew as well.
What is the motivation for the feature?
More complete SBOMs. It will also improve our ability to track CVEs that affect formulae.
How will the feature be relevant to at least 90% of Homebrew users?
It probably won't be.
What alternatives to the feature have been considered?
- the status quo
- another mechanism for tracking non-Homebrew dependencies