[v2,2/3] debsbom: update to v0.10.2

Message ID 20260907123728.335093-3-felix.moessbauer@siemens.com
State Superseded
Headers show
Series Update debsbom tool | expand

Commit Message

Felix Moessbauer Sept. 7, 2026, 12:37 p.m. UTC
This brings a couple of bugfixes, as well as support to read the package
data from a tar file.

Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 ...bom_0.8.1.bb => python3-debsbom_0.10.1.bb} |  2 +-
 .../python3-debsbom/python3-debsbom_0.10.2.bb | 43 +++++++++++++++++++
 2 files changed, 44 insertions(+), 1 deletion(-)
 rename meta/recipes-support/python3-debsbom/{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.1.bb} (95%)
 create mode 100644 meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb

Comments

Florian Bezdeka Sept. 8, 2026, 6:13 a.m. UTC | #1
On Mon, 2026-09-07 at 14:37 +0200, 'Felix Moessbauer' via isar-users
wrote:
> This brings a couple of bugfixes, as well as support to read the package
> data from a tar file.
> 
> Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
> ---
>  ...bom_0.8.1.bb => python3-debsbom_0.10.1.bb} |  2 +-
>  .../python3-debsbom/python3-debsbom_0.10.2.bb | 43 +++++++++++++++++++
>  2 files changed, 44 insertions(+), 1 deletion(-)
>  rename meta/recipes-support/python3-debsbom/{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.1.bb} (95%)
>  create mode 100644 meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
> 
> diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
> similarity index 95%
> rename from meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
> rename to meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
> index 7fc9a8eb..fa0b9b38 100644
> --- a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
> +++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
> @@ -35,7 +35,7 @@ SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
>             file://rules \
>             file://0001-Use-old-license-description-in-pyproject.toml.patch \
>             "
> -SRCREV = "a76d4e784f84e73b98d2bbeadd28c602a8c13708"
> +SRCREV = "00c7cc8b8984251e17a716b14602d20397724b59"
>  
>  do_prepare_build[cleandirs] += "${S}/debian"
>  do_prepare_build() {
> diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
> new file mode 100644
> index 00000000..1aec1369
> --- /dev/null
> +++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
> @@ -0,0 +1,43 @@
> +# This software is a part of Isar.
> +# Copyright (c) Siemens, 2025
> +#
> +# SPDX-License-Identifier: MIT
> +
> +inherit dpkg
> +
> +FILESEXTRAPATHS:prepend := "${THISDIR}/files:"
> +
> +S = "${WORKDIR}/git"
> +
> +DEPENDS:append:bookworm = " python3-packageurl"
> +DEPENDS:append:noble = " python3-packageurl"
> +
> +S = "${WORKDIR}/git"
> +
> +MAINTAINER = "Christoph Steiger <christoph.steiger@siemens.com>"
> +DPKG_ARCH = "all"
> +DEBIAN_BUILD_DEPENDS = "dh-python, \
> +                        python3-all, \
> +                        python3-setuptools, \
> +                        pybuild-plugin-pyproject, \
> +                        python3-packageurl, \
> +                        python3-debian, \
> +                        python3-requests, \
> +                        python3-zstandard, \
> +                        python3-license-expression, \
> +                        "
> +
> +DEBIAN_DEPENDS = "python3-apt, \${python3:Depends}, \${misc:Depends}"
> +
> +DESCRIPTION = "debsbom generates SBOMs for Debian based distributions."

Hm, debsbom (=debian sbom, right?) has no upstream debian/ directory? As
the tool is part of forky that means someone must have done a the same
work already...

> +
> +SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
> +           file://rules \
> +           file://0001-Use-old-license-description-in-pyproject.toml.patch \
> +           "
> +SRCREV = "9b5a5d6be05f1207356223f88b3080bd72722b9f"
> +
> +do_prepare_build[cleandirs] += "${S}/debian"
> +do_prepare_build() {
> +    deb_debianize
> +}
> -- 
> 2.55.0
> 
> -- 
> You received this message because you are subscribed to the Google Groups "isar-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
> To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260907123728.335093-3-felix.moessbauer%40siemens.com.
Christoph Steiger Sept. 8, 2026, 8:10 a.m. UTC | #2
On 9/8/26 8:13 AM, Florian Bezdeka wrote:
> On Mon, 2026-09-07 at 14:37 +0200, 'Felix Moessbauer' via isar-users
> wrote:
>> This brings a couple of bugfixes, as well as support to read the package
>> data from a tar file.
>>
>> Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
>> ---
>>   ...bom_0.8.1.bb => python3-debsbom_0.10.1.bb} |  2 +-
>>   .../python3-debsbom/python3-debsbom_0.10.2.bb | 43 +++++++++++++++++++
>>   2 files changed, 44 insertions(+), 1 deletion(-)
>>   rename meta/recipes-support/python3-debsbom/{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.1.bb} (95%)
>>   create mode 100644 meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
>>
>> diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
>> similarity index 95%
>> rename from meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
>> rename to meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
>> index 7fc9a8eb..fa0b9b38 100644
>> --- a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
>> +++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
>> @@ -35,7 +35,7 @@ SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
>>              file://rules \
>>              file://0001-Use-old-license-description-in-pyproject.toml.patch \
>>              "
>> -SRCREV = "a76d4e784f84e73b98d2bbeadd28c602a8c13708"
>> +SRCREV = "00c7cc8b8984251e17a716b14602d20397724b59"
>>   
>>   do_prepare_build[cleandirs] += "${S}/debian"
>>   do_prepare_build() {
>> diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
>> new file mode 100644
>> index 00000000..1aec1369
>> --- /dev/null
>> +++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
>> @@ -0,0 +1,43 @@
>> +# This software is a part of Isar.
>> +# Copyright (c) Siemens, 2025
>> +#
>> +# SPDX-License-Identifier: MIT
>> +
>> +inherit dpkg
>> +
>> +FILESEXTRAPATHS:prepend := "${THISDIR}/files:"
>> +
>> +S = "${WORKDIR}/git"
>> +
>> +DEPENDS:append:bookworm = " python3-packageurl"
>> +DEPENDS:append:noble = " python3-packageurl"
>> +
>> +S = "${WORKDIR}/git"
>> +
>> +MAINTAINER = "Christoph Steiger <christoph.steiger@siemens.com>"
>> +DPKG_ARCH = "all"
>> +DEBIAN_BUILD_DEPENDS = "dh-python, \
>> +                        python3-all, \
>> +                        python3-setuptools, \
>> +                        pybuild-plugin-pyproject, \
>> +                        python3-packageurl, \
>> +                        python3-debian, \
>> +                        python3-requests, \
>> +                        python3-zstandard, \
>> +                        python3-license-expression, \
>> +                        "
>> +
>> +DEBIAN_DEPENDS = "python3-apt, \${python3:Depends}, \${misc:Depends}"
>> +
>> +DESCRIPTION = "debsbom generates SBOMs for Debian based distributions."
> 
> Hm, debsbom (=debian sbom, right?) has no upstream debian/ directory? As
> the tool is part of forky that means someone must have done a the same
> work already...
> 

There is an upstream packaging [1] which is also maintained by us. 
Unfortunately debsbom is only available in trixie backports and not at 
all in bookworm. When we introduced the SBOM support we needed to 
package it in isar since it wasnt yet packaged upstream and it has 
stayed like this since then. We will at some point probably just use the 
upstream version.

[1] https://salsa.debian.org/python-team/packages/debsbom

>> +
>> +SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
>> +           file://rules \
>> +           file://0001-Use-old-license-description-in-pyproject.toml.patch \
>> +           "
>> +SRCREV = "9b5a5d6be05f1207356223f88b3080bd72722b9f"
>> +
>> +do_prepare_build[cleandirs] += "${S}/debian"
>> +do_prepare_build() {
>> +    deb_debianize
>> +}
>> -- 
>> 2.55.0
>>
>> -- 
>> You received this message because you are subscribed to the Google Groups "isar-users" group.
>> To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
>> To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260907123728.335093-3-felix.moessbauer%40siemens.com
Felix Moessbauer Sept. 9, 2026, 5:48 a.m. UTC | #3
On Tue, 2026-09-08 at 10:10 +0200, Christoph Steiger wrote:
> On 9/8/26 8:13 AM, Florian Bezdeka wrote:
> > On Mon, 2026-09-07 at 14:37 +0200, 'Felix Moessbauer' via isar-users
> > wrote:
> > > This brings a couple of bugfixes, as well as support to read the package
> > > data from a tar file.
> > > 
> > > Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
> > > ---
> > >   ...bom_0.8.1.bb => python3-debsbom_0.10.1.bb} |  2 +-
> > >   .../python3-debsbom/python3-debsbom_0.10.2.bb | 43 +++++++++++++++++++
> > >   2 files changed, 44 insertions(+), 1 deletion(-)
> > >   rename meta/recipes-support/python3-debsbom/{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.1.bb} (95%)
> > >   create mode 100644 meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
> > > 
> > > diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
> > > similarity index 95%
> > > rename from meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
> > > rename to meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
> > > index 7fc9a8eb..fa0b9b38 100644
> > > --- a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
> > > +++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
> > > @@ -35,7 +35,7 @@ SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
> > >              file://rules \
> > >              file://0001-Use-old-license-description-in-pyproject.toml.patch \
> > >              "
> > > -SRCREV = "a76d4e784f84e73b98d2bbeadd28c602a8c13708"
> > > +SRCREV = "00c7cc8b8984251e17a716b14602d20397724b59"
> > >   
> > >   do_prepare_build[cleandirs] += "${S}/debian"
> > >   do_prepare_build() {
> > > diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
> > > new file mode 100644
> > > index 00000000..1aec1369
> > > --- /dev/null
> > > +++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
> > > @@ -0,0 +1,43 @@
> > > +# This software is a part of Isar.
> > > +# Copyright (c) Siemens, 2025
> > > +#
> > > +# SPDX-License-Identifier: MIT
> > > +
> > > +inherit dpkg
> > > +
> > > +FILESEXTRAPATHS:prepend := "${THISDIR}/files:"
> > > +
> > > +S = "${WORKDIR}/git"
> > > +
> > > +DEPENDS:append:bookworm = " python3-packageurl"
> > > +DEPENDS:append:noble = " python3-packageurl"
> > > +
> > > +S = "${WORKDIR}/git"
> > > +
> > > +MAINTAINER = "Christoph Steiger <christoph.steiger@siemens.com>"
> > > +DPKG_ARCH = "all"
> > > +DEBIAN_BUILD_DEPENDS = "dh-python, \
> > > +                        python3-all, \
> > > +                        python3-setuptools, \
> > > +                        pybuild-plugin-pyproject, \
> > > +                        python3-packageurl, \
> > > +                        python3-debian, \
> > > +                        python3-requests, \
> > > +                        python3-zstandard, \
> > > +                        python3-license-expression, \
> > > +                        "
> > > +
> > > +DEBIAN_DEPENDS = "python3-apt, \${python3:Depends}, \${misc:Depends}"
> > > +
> > > +DESCRIPTION = "debsbom generates SBOMs for Debian based distributions."
> > 
> > Hm, debsbom (=debian sbom, right?) has no upstream debian/ directory? As
> > the tool is part of forky that means someone must have done a the same
> > work already...
> > 
> 
> There is an upstream packaging [1] which is also maintained by us. 
> Unfortunately debsbom is only available in trixie backports and not at 
> all in bookworm. 
> 

While debsbom itself is available in trixie-backports, the python3-
spdx-tools is not. By that, we can only generate CycloneDX SBOMs in a
pure Debian environment. For older targets like bookworm, we anyways
need a custom built in isar.

As the debsbom tool runs outside of the target chroot, it could also be
provided as host tool (e.g. in kas-container), or in a dedicated
(forky) chroot. The latter requires multiconfig for all targets that
want to have an SBOM generated, though.

> When we introduced the SBOM support we needed to 
> package it in isar since it wasnt yet packaged upstream and it has 
> stayed like this since then. We will at some point probably just use the 
> upstream version.

While we could use the upstream packaging, it would significantly
increase the build time due to additional built-time dependencies
(which are optional if only supporting debsbom generate). We could
introduce build profiles in upstream to reduce the impact, but I'm not
sure if it is really worth it.

A third option would be to use Yocto's buildtools feature [2], but that
is currently not used in isar at all.

For now, I recommend to just keep the packaging as is and just update
it from time to time (only needed on generate related patches).

[2]
https://docs.yoctoproject.org/dev/ref-manual/system-requirements.html#downloading-a-pre-built-buildtools-tarball

Felix

> 
> [1] https://salsa.debian.org/python-team/packages/debsbom
> 
> > > +
> > > +SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
> > > +           file://rules \
> > > +           file://0001-Use-old-license-description-in-pyproject.toml.patch \
> > > +           "
> > > +SRCREV = "9b5a5d6be05f1207356223f88b3080bd72722b9f"
> > > +
> > > +do_prepare_build[cleandirs] += "${S}/debian"
> > > +do_prepare_build() {
> > > +    deb_debianize
> > > +}
> > > -- 
> > > 2.55.0
> > > 
> > > -- 
> > > You received this message because you are subscribed to the Google Groups "isar-users" group.
> > > To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
> > > To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260907123728.335093-3-felix.moessbauer%40siemens.com

Patch

diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
similarity index 95%
rename from meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
rename to meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
index 7fc9a8eb..fa0b9b38 100644
--- a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
+++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.1.bb
@@ -35,7 +35,7 @@  SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
            file://rules \
            file://0001-Use-old-license-description-in-pyproject.toml.patch \
            "
-SRCREV = "a76d4e784f84e73b98d2bbeadd28c602a8c13708"
+SRCREV = "00c7cc8b8984251e17a716b14602d20397724b59"
 
 do_prepare_build[cleandirs] += "${S}/debian"
 do_prepare_build() {
diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
new file mode 100644
index 00000000..1aec1369
--- /dev/null
+++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
@@ -0,0 +1,43 @@ 
+# This software is a part of Isar.
+# Copyright (c) Siemens, 2025
+#
+# SPDX-License-Identifier: MIT
+
+inherit dpkg
+
+FILESEXTRAPATHS:prepend := "${THISDIR}/files:"
+
+S = "${WORKDIR}/git"
+
+DEPENDS:append:bookworm = " python3-packageurl"
+DEPENDS:append:noble = " python3-packageurl"
+
+S = "${WORKDIR}/git"
+
+MAINTAINER = "Christoph Steiger <christoph.steiger@siemens.com>"
+DPKG_ARCH = "all"
+DEBIAN_BUILD_DEPENDS = "dh-python, \
+                        python3-all, \
+                        python3-setuptools, \
+                        pybuild-plugin-pyproject, \
+                        python3-packageurl, \
+                        python3-debian, \
+                        python3-requests, \
+                        python3-zstandard, \
+                        python3-license-expression, \
+                        "
+
+DEBIAN_DEPENDS = "python3-apt, \${python3:Depends}, \${misc:Depends}"
+
+DESCRIPTION = "debsbom generates SBOMs for Debian based distributions."
+
+SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
+           file://rules \
+           file://0001-Use-old-license-description-in-pyproject.toml.patch \
+           "
+SRCREV = "9b5a5d6be05f1207356223f88b3080bd72722b9f"
+
+do_prepare_build[cleandirs] += "${S}/debian"
+do_prepare_build() {
+    deb_debianize
+}