<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does it make sense try to make a SBOM file for Power BI Custom Connector? in Developer</title>
    <link>https://community.fabric.microsoft.com/t5/Developer/Does-it-make-sense-try-to-make-a-SBOM-file-for-Power-BI-Custom/m-p/3758889#M50368</link>
    <description>&lt;LI-CODE lang="markup"&gt;At least with my knowledge, I don't know if you can do something "harmful" using Power Query M language in terms of using the language.&lt;/LI-CODE&gt;
&lt;P&gt;Unfortunately, that is possible. Depending on the scope of the credentials used in the connector your native query can include insert/delete/update etc statements affecting your data source. Power Query can also run Python and R scripts that can equally contain destructive payloads.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2024 20:29:01 GMT</pubDate>
    <dc:creator>lbendlin</dc:creator>
    <dc:date>2024-03-12T20:29:01Z</dc:date>
    <item>
      <title>Does it make sense try to make a SBOM file for Power BI Custom Connector?</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Does-it-make-sense-try-to-make-a-SBOM-file-for-Power-BI-Custom/m-p/3756468#M50327</link>
      <description>&lt;P&gt;I'm, making a custom connector for the company I work for, but based on the DevOps and TI deparments, If I want share the connector be used in the company I must meet certain requeriments and one of the is a SBOM file to determinate everything is ok.&lt;BR /&gt;&lt;BR /&gt;But is it possible or makes sense generate a SBOM file for a custom connector?, TBH, I don't know if is possible or makes sense, having in mind that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You can see the source code of custom and certified connectors just unzipping the .mez/.pqx file.&lt;/LI&gt;&lt;LI&gt;The connector needs Power BI Desktop to be used or perform something.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;At least with my knowledge, I don't know if you can do something "harmful" using Power Query M language in terms of using the language.&lt;/LI&gt;&lt;LI&gt;I cannot think in any dependency for the connector.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Besides that, is there a way of do the SBOM file for a custom connector?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 00:16:19 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Does-it-make-sense-try-to-make-a-SBOM-file-for-Power-BI-Custom/m-p/3756468#M50327</guid>
      <dc:creator>ECorona</dc:creator>
      <dc:date>2024-03-12T00:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Does it make sense try to make a SBOM file for Power BI Custom Connector?</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Does-it-make-sense-try-to-make-a-SBOM-file-for-Power-BI-Custom/m-p/3758889#M50368</link>
      <description>&lt;LI-CODE lang="markup"&gt;At least with my knowledge, I don't know if you can do something "harmful" using Power Query M language in terms of using the language.&lt;/LI-CODE&gt;
&lt;P&gt;Unfortunately, that is possible. Depending on the scope of the credentials used in the connector your native query can include insert/delete/update etc statements affecting your data source. Power Query can also run Python and R scripts that can equally contain destructive payloads.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 20:29:01 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Does-it-make-sense-try-to-make-a-SBOM-file-for-Power-BI-Custom/m-p/3758889#M50368</guid>
      <dc:creator>lbendlin</dc:creator>
      <dc:date>2024-03-12T20:29:01Z</dc:date>
    </item>
  </channel>
</rss>

