From patchwork Mon Nov 17 13:24:35 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Felix Moessbauer X-Patchwork-Id: 4605 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Mon, 17 Nov 2025 14:25:08 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-qk1-f188.google.com (mail-qk1-f188.google.com [209.85.222.188]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 5AHDP6WV025234 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 17 Nov 2025 14:25:07 +0100 Received: by mail-qk1-f188.google.com with SMTP id af79cd13be357-8b225760181sf542203885a.2 for ; Mon, 17 Nov 2025 05:25:07 -0800 (PST) ARC-Seal: i=3; a=rsa-sha256; t=1763385901; cv=pass; d=google.com; s=arc-20240605; b=HDMVn4GfKT0fOaj+8cZp3daEl9DxOxTwWvYb+LcEKMdAa/d2cjj4RfXXzgWbS7lbhV VXbG+a1F7Io5YrJTJdZNGTD7uaBbOQrU4+N7xfZjA45FERt7DVdyA27fZpZpo6clYUQr KCkIL9abcUQFeTF0wC4QMujWWQuJXw/HsrlarRKILdHQPu6Rwq5g1rXjAq349Dpb+KAx BXibqEu2CGKiffwrKRv+uPeTJZ/PXqjTlP6/0p9+V/3SlsDZudeVh6KGm9xZzaLe9qea H987MR1Opw7fbnaprWDYBDFs3kBdh7eQQHNXf6ls7PqzZ9kXPmlAbBisY7tuLil3+QMH OkSw== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:dkim-signature; bh=1mA1oTKGYQL0PjeZUQOIYdyU8WG0hu+LgxB1s/mQaeY=; fh=WL9u8FvC08mdZrATCAyyGSP4R2+Qbr9hqzOn4LVKOuI=; b=dxApyzLe2SDOCFjAQEVQqTJ8xKY9SqWZl3F6DifLE1FOJO2hOQRvknYI1feRYk2DgH lQoXN4rRRCqc43gPntg8c8Y8WMgl/XPgfqGiBqoq06cFIqEBpDKVGJZuZz5Mu3JT4saW oKHAwrFtvjAVQoFyvbr95WSZbQ6EqVXdRXvSCvSeUbGMNM+Gtc7xmshxRG5eVnNhh3ZK KVYxURaP2VQ2IX7ztuztelJ3oh8ujih0/NwvniV3oxelKHE9tt24lgVRgcouTIqQLu1e Fb0E22adpXB/pv630eTvbpj9/wX0b2DGvk3+vQFBTJSYaCh5EMTOI4/+gGO4MGLOFubz GQyw==; darn=isar-build.org ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b="VnYZTY/O"; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1763385901; x=1763990701; darn=isar-build.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from:from:to :cc:subject:date:message-id:reply-to; bh=1mA1oTKGYQL0PjeZUQOIYdyU8WG0hu+LgxB1s/mQaeY=; b=jXcSBKKuq/0zIxy2N7/n89ncZ9E82D1HHi4tAgSNzyf/SEeomox/nrV4ebDzj4IvQ1 VlbUVks9s+1ALUfEmVVcIhxp6ZTeSu4/AuJBWcsGQva3AKhmFAgPi5l7vBzM9h60pIUi bztF49WOT4eGNn5NmL5zHWs3yNFPis5NXxIqtOgxu9lI0z8qqsCivk8iNYTHjw2Oz+uP IZisysbYmxElNyRGMqKYP1CNJolvojTteLylRVzxdcc4tZyegIYNKBMJtMhRyYs8vH34 jrmLItan/8nKPyoKRX8EUSWVDhoyLG6r7z0BKTODsfXWBQn/8TWyTPycq8PZXV6UuxTj 1Mdw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1763385901; x=1763990701; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=1mA1oTKGYQL0PjeZUQOIYdyU8WG0hu+LgxB1s/mQaeY=; b=Mjjtv9ApeaABnzlm22SdzoPwl92Ou/RopqE6jgzG4c4FLacsGtUi1RacoGMG9YmtCS rIGfA+NR1vrwEOZoDwssZvo6xkf7A2BZpF9yC5yqZnlkv5MQNQHHH6CEHhiZvfUH/xcz GY+upEVE20pan7d22ADRyKCBuHAJxjbYgYN9NOpzlv0pv+MB44jG9dg1+BT2Pf+ovI8h RrMzZvFterQEbQu+yZae8BHubeguIa2gDo3t/ppAvMoCiGosLORXtLNotfgPZpLhsH7D fDwUkJi3U0BHiK3kQUARaOeH0E9n8wjjz/4cnZbfWdcdDpKrIzkfyeKo/+sibZ71/n3F 0yHQ== X-Forwarded-Encrypted: i=3; AJvYcCVUfUJA1jy4SysSXOTz3gPf+HtuUAnQ3txB4sdteRzvI6mL+jqMGlp67sG7/vRyCKEKMzN61V0=@isar-build.org X-Gm-Message-State: AOJu0YwFNOcAsirGc6PtYZICHol2YBhA1AuOB6DjxTvOy58Tjhp+guox zMGF01bxX40Z7qZifTy6LzM77NjFGUvgRHPGfP0lTInmM0Dgd15y4Ww1 X-Google-Smtp-Source: AGHT+IFzvaL/J20uevp7MChe05sISPWl8T5FDN1knOma8gX3woXtSsss43l+cUXyU3HtFBBR7wEVbw== X-Received: by 2002:ad4:5d66:0:b0:78e:e166:72ac with SMTP id 6a1803df08f44-882925a39c8mr160476746d6.9.1763385900784; Mon, 17 Nov 2025 05:25:00 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+b9vv1tDe2HpS5tLkJOFR79wCVsQJX5KUTyXudHn2GJ3A==" Received: by 2002:a05:6214:27c8:b0:882:48cb:241e with SMTP id 6a1803df08f44-88281af8834ls80692886d6.2.-pod-prod-08-us; Mon, 17 Nov 2025 05:24:59 -0800 (PST) X-Received: by 2002:a05:6102:38ca:b0:5db:ebb4:fde3 with SMTP id ada2fe7eead31-5dfc55371a8mr3607158137.16.1763385899455; Mon, 17 Nov 2025 05:24:59 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1763385899; cv=pass; d=google.com; s=arc-20240605; b=kDyliVuqwMsdeYLI47DtXeBDxkCseBILgxOocVMvu0pWhQMV54ihKhsZGbdFOGC7f5 jVb1qvDwUR3L8Al/pPQ0dLme+DAhTe28g1ybv/pviSR+ajdU1vTN/apInN+lgF7Vjk1P Q0Xz3dpmDv1UBQP40oru30I6gtaOjlEpaNgImYMhWk4qpZz6pSea9giMpedQjtpR/xyb VAZWqRpWNZEgY3mkJkENE39NEDSpgWs3pXD1vGI9gDoa81gM35tKKUat+4hDX8homaEM 8o8gtPjFN9mUU/loJngg7Y2Xo4kI915ozuYHpPksk1IHvfS6pDqaqpn4zb6M3861qyHU feuA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=eELwxLZ8Ccv1VNPXZgZh33ZMUcEizbdWouahKyXZrNg=; fh=U8bm4dTYQmv4LpgB7HlcKSsNa947JBNKOeDeOLKSao8=; b=cQCaxXCjaRxP5ytyuHfGosQLhQuSyWgT3S1p2GvZi8WcDYyd5z569DY+eEtO1Q8NaU ykvP5Qk+UtWcPvn7NWzX6YSNAyGbKnVbY98IGlC0B5KvBAWhMFE2oJ3b8j9rrJzBp313 echW33B6MZ2wjAhew8i9LmHqdsABl8AO7wz67HisOS4otbbMIXubBBC5J4NaBp2r4+1b 5OxEh/7zbuWDGf+ygptoVduMdsAYCgH9Mb2JbL2pZAIgpwIbQtOexLCDqN7hABlQGkpn dQFKQvq/A4CnPS+DfzSw6M0u6CsRZ/7stu3ZNKU0sL5RpR7578tvHdtJx6H3fEzwNve1 Rzvw==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b="VnYZTY/O"; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from GVXPR05CU001.outbound.protection.outlook.com (mail-swedencentralazlp170130007.outbound.protection.outlook.com. [2a01:111:f403:c202::7]) by gmr-mx.google.com with ESMTPS id ada2fe7eead31-5dfb71a44bdsi220418137.2.2025.11.17.05.24.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Nov 2025 05:24:59 -0800 (PST) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) client-ip=2a01:111:f403:c202::7; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Sr58sq47s/cAKzNa3kMR334PwafR3VTH4wW1MYp1QunMEpBAQEeYZa7wDpo1x/HeEChW74RKU3x6T6BZlJkaGUiGIxcrysoR/xoUWQdC8NBS2hqaI9qLyhGxYfYsxzucGZ1miCFAYAMLjBJx3guhMeYjFJWtEQTSpDo92XzZ3FUPaRc7pfYJ2AnheuI1o2gXzuMMA7fuRQJ+yWjbYgrF17GsudzHWz2q70nlzeMUTHuWArWcEusobcGuzOiV8oGaGqxfPAD3Y+kpYafdQMEzjMIPi7e+HOeVSe2yhsSYAW2mSYtbgCWUr9O3ycBYtCPMLH9ApAelcb56HGapzfdU6A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eELwxLZ8Ccv1VNPXZgZh33ZMUcEizbdWouahKyXZrNg=; b=l8vdowld4RelpX17z/DC+f12v7zqamajOpU36OIZbDlphoSBBHDDOPIPxT3WZXs8wLM97RwP9HRNeg5noaDE3aGBDU+Q1/2YJtzqxb3PPQMBqfgpnj+XuqQSs1NPkBl3DIEpduMLDTfObOveo2wuOoBK9gDWlX9OSKMGZYO/7G6qx8XDLkK3hYs7eC6meT4ZVYrofgLPAMR5TerJiO+8rLaQ2bf2Qt6KxMGfYMrb04lCJGrcUIMTA71KRA8jSys2nGuG259uwra7OtJG1x+Xav2lKaTgy0XK3IORtN66fG/f6wx0pHfQfisUDaAa5XkwI6o13hjKjSAk1yQBoz8Mcw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) by DU4PR10MB8513.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:561::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9320.17; Mon, 17 Nov 2025 13:24:53 +0000 Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe]) by DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe%4]) with mapi id 15.20.9320.021; Mon, 17 Nov 2025 13:24:52 +0000 X-Patchwork-Original-From: "'Felix Moessbauer' via isar-users" From: Felix Moessbauer To: isar-users@googlegroups.com Cc: christoph.steiger@siemens.com, cedric.hombourger@siemens.com, jan.kiszka@siemens.com, Felix Moessbauer Subject: [PATCH v4 09/10] imager: create SBOM of IMAGER_BOM packages Date: Mon, 17 Nov 2025 14:24:35 +0100 Message-ID: <20251117132436.511686-10-felix.moessbauer@siemens.com> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20251117132436.511686-1-felix.moessbauer@siemens.com> References: <20251117132436.511686-1-felix.moessbauer@siemens.com> X-ClientProxiedBy: FR5P281CA0026.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:f1::11) To DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU0PR10MB6828:EE_|DU4PR10MB8513:EE_ X-MS-Office365-Filtering-Correlation-Id: d34d60c0-6658-4400-36c9-08de25dcb0a3 X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|366016|1800799024; X-Microsoft-Antispam-Message-Info: lQVzrMHzRIVptnAtWn3IdXL0R111pydvnba9ebAjFTrBLjO0Ht5xbT7kkWSJC1HYX75ZFrfFCyTfn2KEauJuxn7esJJEh/xy0m63IOXkmAr5Vafhoicpup/FdmUanU+LUgBDTK60KStSo/KccGcP66I+cnECouSdDdAr/1Zpq47HB6Eh9S80e2JeDY4Wcldt2d/qB2RKVUhn9KVHZPnXNHxpOJyFwoIs5bbtfLVB1WVQ5ph6mFwzO02Oxp7jQT7IZD3XSolwr7t3sP0o2ssjiyiu+u3d0o4qTrOrh+wElzP/Uo4KUZJ2euokTkIr+wpgWaun0F8vTrcXvTELbLJZ+R0V9uZ51W3z7Wq/wMgAuFXJLxwaTVnyV1Y/1CXYeT9X6wtwUXerH6CJiBzvMTGmVzCkj0IZRj9fNSeSeo8EB+UjSugcPzFEHNt3NgCPbsStBr2NIJpZl8lAFIds1K1ATbzh7EAIR9AEyU7WJ2du13NqOG0Neb9KRmJqk7VjfsM2Yg+59oD68cLUuojWK/OieqYHM8bUZPEbwQA5JACxKRWKumxrwLiUBp3PVpJ8wf8U4AjibH7Ej0RZWfG7z464zbYBp16HRw9yitBymjU8AhzBYwFfE+Q3rL6VWV8GSWaq8lSxdkFvFdNlCfE0woVU2p9orjsFj6ebTu8KaSaMqttrnz/J2nfZ/a1fAW5C2WaJNvkU3bYsKg2jC9Nmc9qbMNHR0upieRQSLcBl/dlP6/vB3b4Rz6GysrTxokIfbsvY6qSdbYrqnLYEyiuEcDBa4HvsgVPFH5sWs6lQdBLeWMcu4Vd1ZtfBsyF6j5m0M1NFrpBJa4ZAiBitisYkjzUSmaL9WkREtgPG0p6BwcvO8adzczs4IfEtm/5TcDetkwSk6484RlsSr2OPZWDNZCygXF0bKDr5JYgbcnS75oq68palLANpk/DC9lovVnSu7JintZKIiiRGgzTinPKJOYEpj7tH07y8QpIN5LxZV6Th/305pOUnwyHp320KvlMqOLXJsg8LAS0bC0cWyG+jRMCQ9ggI2dsRcB5eGc2cAx140ZORhhWpgXD90AA6w9/1G0IHxXXLE6700XxCWpMtDRZp11bt3FRwVpY4Rf0DFI54RfG3TNGbed+bSDk5eAnLQH3NCcckR3EPqWv9OhFirWK42Q5ic6Z7J/18a5LR7SCHOiVMDHWDzmDRs+3/q3QwuDLnJYh3Q9LemVpFzyspcwa9oF8qogry4jAaMu3FUUUU9v62rztyaKOl5lxL1mLVJWfhXIaLTC/vPh1yj1HhXuM4+dWVD4QaGl7ydDiPmEQUYkZtwr8XfkSVS9OsQAIx6bsU4ZjIgEKKMOQSG/iwlj6jEGLWg3pzZshYuQMmWymXpCCavtTTC2YIe+gYkrDoBMzOcoUAo2i+X3jvjM9HQOPeGrUOB+m2AbKjA3SfeiTuFgtQvUeoUqfVGMBTW4+1I/D6 X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: fTDX+9R5QyJSLSe7jUfmj/vlKZHGbzmU7RmF/9WxHW9BCwOEuUfiwbE/W2iRT8Xi80pI8+CzqIzfcd7S5LuDAG6w7LkR3NVukUlkQwxdrCzxP10TtvuTXSAVzvu3/lyMfIZBNaK1yqENSR0U9NqyI5MchArMs9Ipfp+3eweEhDDEfOAjfkQgWnCZj3T+TugrpQpgbXy+Ary7lkpnCZE8xH5aeI5VQL9sQpmPVcdeCfbI0JqvUqU6aYMma6uDaZgYPDd8KTmZAe38unwbh0GN1kwP4QW9iIrY8cT7iiWZVSce0tDzp4BemwWmZNXCbEOrp6KcLiF7xVyL4IXdClIzF7phfMvbm14W7IvNY2dqHKM50uDeqa8dhQXe3ARk8N4G2FXanCdEYrdESd5GvVOG+QZp5BQvKisvYo23GckZhO02AYmXOuW+S2gQ4xFlxW6tAqgo3VMCMSw19RnajKBE76hlhjPaEsZGdX4BGX8xceh2rVMqF6K7avLeL+TqiiuH3QF2p/sO/bHKmYFYRKWGGIjaJToikduWs+ipXArecDZb1lmerQRmC8ClBxgGpKnTTZjZ6lSw+14hKTrp0Tup6OVh8LjPrrNaudcHqNrn0Kuj1+b/hQin9KbsaFlURdYo1QbAsrz251rUrDmTN5xWR29q5WDvyTX962Yv2S1Y27Xkcie209pPpTxvGJqJ238yKBiKbFMnJloXRx2gUeiaY8bfASV2zSYWk8ZTPbqleCecm1Qx15PynsQLOm9mEavH+rE9lcMZeAseKVtANefh8oBzEBk6aW5K/SmrXGFDmvB8/lIJWeeyCxG/Jh2f1THDwxAbCrQki1gtzH0Sv2uD+8jmVQMW8MCssrGTziplzDtYFbtHFBkZrYq0iHfpUv+f4VklTw3qFEhDxrhFvdf38xXrtHHeZiZf21elzJtUtNUAAP20waFc1kpUEwrx1/sbz8X0NbFnDSEUlzsvsQnYkQst6z+pBHwuss0GGNPWYfIamqzWFAYJtjaLzISbFBpLqzc5DQnlwJMcWBSJQL41iedfaDThAB7RgDwra3NsNWiJUeNDVLavUrXAbwEtdOiGfz95Qg1E61OMveQz5q60LUNuvruH72BuB0hoTObcjuafGGeHmqmVIa7G3Wh7s87V4hR2oDtTJl7VlTDuFWOHMpYtszkFKPfHj9vlS23CVLPC9a+k5SKgVRC5qWuX64MvG/meTquFDjxcJJMYoPvyzCtlNdMyIdVb8YkcG/Si9rkQODopcQ0uboNKpTfommnkEcVbTpR5GAq3I1cKKhWKKyLw4gViLaZEKkdDlEf+KTm6Z8AOoXdibAt2HEssmQxD5LzMMRRVrk3W1hw7ZPzdzClANmpeumjHBYFi8pu6T/yJrfEKxoH/FuAAg1MiAwfdezjP0pEKueVD2u6OAr1RovFgB11GaUBXI59Fm60dYcxSdUkN5BhlC+roxyARuq6BcCs+CEi+p1xpnMFYfpf0dYIHDPwrLgI+nM5OiCIhx/3FJDpzQRU0h6cl1XbVk6hKpoWYY2C6EJt8cuaIS4lMUWEy4B+fThlM+IYJ+4diukc3RWzp7UA0bko2gXsLTaMlVIAraoPbs1SbDmtxf8s8Sg== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: d34d60c0-6658-4400-36c9-08de25dcb0a3 X-MS-Exchange-CrossTenant-AuthSource: DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Nov 2025 13:24:52.1556 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 1c64A8BG4NqkzQWiYOXhHACxjBZbjQjFw5iwb6Vs+nwWl7wh900AMkqB+YFgEVwZrnajjgXK4yJbrGHVL2/7Xk/GChDq7aNCqk71Xi7ltxc= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU4PR10MB8513 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b="VnYZTY/O"; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Felix Moessbauer Reply-To: Felix Moessbauer Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= This uses the same interface as the .manifest file, but adds the packagse to an SBOM. Signed-off-by: Felix Moessbauer --- meta/classes/image-tools-extension.bbclass | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/meta/classes/image-tools-extension.bbclass b/meta/classes/image-tools-extension.bbclass index 2027effb..95f003d0 100644 --- a/meta/classes/image-tools-extension.bbclass +++ b/meta/classes/image-tools-extension.bbclass @@ -73,6 +73,8 @@ EOAPT schroot -r -c ${session_id} -d / -- \ dpkg-query -W -f='${source:Package}|${source:Version}|${Package}:${Architecture}|${Version}\n' ${local_bom} > \ ${WORKDIR}/imager.manifest + + ${@bb.utils.contains('ROOTFS_FEATURES', 'generate-sbom', 'generate_imager_sbom', '', d)} fi schroot -e -c ${session_id} @@ -80,3 +82,23 @@ EOAPT remove_mounts schroot_delete_configs } + +generate_imager_sbom() { + TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH}) + sbom_document_uuid="${@d.getVar('SBOM_DOCUMENT_UUID') or generate_document_uuid(d, False)}" + bwrap \ + --unshare-user \ + --unshare-pid \ + --bind ${SBOM_CHROOT} / \ + --bind $schroot_dir /mnt/rootfs \ + --bind ${WORKDIR} /mnt/deploy-dir \ + -- debsbom -vv generate ${SBOM_DEBSBOM_TYPE_ARGS} \ + --from-pkglist -r /mnt/rootfs -o /mnt/deploy-dir/imager \ + --distro-name '${SBOM_DISTRO_NAME}-Imager' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \ + --distro-version '${SBOM_DISTRO_VERSION}' --distro-arch '${DISTRO_ARCH}' \ + --base-distro-vendor '${SBOM_BASE_DISTRO_VENDOR}' \ + --cdx-serialnumber $sbom_document_uuid \ + --spdx-namespace '${SBOM_SPDX_NAMESPACE_PREFIX}'-$sbom_document_uuid \ + --timestamp $TIMESTAMP \ + < ${WORKDIR}/imager.manifest +}