From patchwork Mon Nov 24 11:46:37 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "MOESSBAUER, Felix" X-Patchwork-Id: 4635 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Mon, 24 Nov 2025 12:47:39 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-yx1-f56.google.com (mail-yx1-f56.google.com [74.125.224.56]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 5AOBlb01030970 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 24 Nov 2025 12:47:38 +0100 Received: by mail-yx1-f56.google.com with SMTP id 956f58d0204a3-6421389b8b7sf5835328d50.2 for ; Mon, 24 Nov 2025 03:47:38 -0800 (PST) ARC-Seal: i=3; a=rsa-sha256; t=1763984852; cv=pass; d=google.com; s=arc-20240605; b=eKB7Rw7bR5RQdzfvklUewohrqX8wS8C9Wv/E+vCOoEbIMYBi+BTF8dqGpI//4asjdi 4sUFKch+AcYkGoYqUSvxNDbmaDUUzEuYQ/lrgYa6y7BgpGboeIdG+1hnQRZZLkIfxlb0 3U7loeFEhfpNCgopFN+WP2lncigVO/uNDjq61OeCp9NU5qfkuz7UmsxqLjozI/sFwgul OMw8XKknFBfub/ebzICwd3MK2yaZdctgEiiDQCzPh6X6YqOBIwRuUqVjzb9AvUHQ6lds 91F5T1xODlAjYi2FdMqkcyIuSWWysB1j4A2Key375niroMrkE0YmsuYjORufRVJe6l1r Un7A== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:dkim-signature; bh=W5c4CepbLLA6z/6HpLfEwAP35PGKmOO0UMSjlBcsU44=; fh=mTIpY1uVgHBeQGivNbxTI0ykyRgcBgsBjFN/o6EFGNQ=; b=i4y9AAXoJh18J4oRcGU1tJbFBhNT91TQUfq96U0mxqPsdkYZHg+LHKDYCbSPXXoLA+ jcmzp1nvsNyyFjdv6qyJ2HURZuDCEm7mIlcKPWBIctAzaj0fe6FnYfay1ZdWTzCW2ziQ p6b13Wm6p2V5QXLjTRXBJABlSDNgKaP4nsuinI8td4RFQJyxEalkQxtim+hvkvqolsWt SzqER8B0/U5/dfI+8XFP0DqHHFDTykiz1bMJTwMoD8qo4XBUPW3THTPAYDOheUUIfJ0P oM0MlihmBvxgM0xno52cMyCZnVdvIfRhST3XvtQko2jyaLkoUicBmt4nbjbZ/HLOlGFq hROw==; darn=isar-build.org ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=RogAhB9d; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1763984852; x=1764589652; darn=isar-build.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from:from:to :cc:subject:date:message-id:reply-to; bh=W5c4CepbLLA6z/6HpLfEwAP35PGKmOO0UMSjlBcsU44=; b=VwjrL5lgF+4M+difXyXN/WA1JTXvaAMsT0bhCh9fDtpIt9P1nH7SHPnC/0zsJBpZYB YY5XHX2awTJZyTafecKy9Z5lLmevLYiC4vMzxlQjfSw7W6w9HPWzB055dICVJKEw8les j4pzUncVnZyy0Rh3s/eYKtsqGjLaRNRSKdbDTLuj1TkOHcWWwMc2QVUQauTsgiDOnrKM i3K4TNJ/KCTUbraGDlJTPaSTpltYI7EkNvrZ03ssEGiRNe8Rkj6BtPQwzP+APb4/upVu 3npj1ZFTP3sV6E1Rpc+WgLBFHBbBuJRb9e8vfGjRBSjzULBK0ATW4ORxM72Ims9IxMQq eUpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1763984852; x=1764589652; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=W5c4CepbLLA6z/6HpLfEwAP35PGKmOO0UMSjlBcsU44=; b=irw4+Vr/qTM46KlbrOiN4Xfq7iHi6J8f4kFASDwi53CqFiZ8IuoljSbUaxYL9HKawD R6zqQnPHApsKCqK1tQiIOBhHgyex9FQlsGJTKsNkmcJb0gIU40tvLh4Ovh4v2y5zq9la eEKOqSDgpEW5m3XvNVioTRirZa2cdPc/EY/zJI4L13GN7NZdSi8xmVpztzeCdugxvQs4 dJzFM3d3ZeACJKV9oKWPtAzzopj2DXB73d6JBFcavt1XqCSjsiCHdqILAYsfUqQ3w4ya Sjr2OL86zU3jTUSVTX/MgjTtmiOztcmcDTr/5+DJHGPpQP7w2rVP06U6f8QAFhuOWv5c Cr9w== X-Forwarded-Encrypted: i=3; AJvYcCUXmTksnb4I4XYMGygnZa6ulLH2VJBhhioglQPptt6Rr6/urJgDaJ4L5QaVCOYdvfM+dMARLV0=@isar-build.org X-Gm-Message-State: AOJu0YwdLleKLMjpRkvSubnuLRNy6Sbpxpd+zxNExsbc1UZ42seh+PYQ AEuTjk3IcK/WBu0mMYj9I19SqUdIk9yQeG/VH1CUdoy5GSe0UcRvRWri X-Google-Smtp-Source: AGHT+IFF93ByewykAtzDdLHaHueCbZclHDhgKnHo+SErny8qYi+XX2LBmst8Zkh3Tr+hht93k7zVVQ== X-Received: by 2002:a05:690e:1555:20b0:63f:cdd3:11f3 with SMTP id 956f58d0204a3-64302a75173mr7019467d50.37.1763984851998; Mon, 24 Nov 2025 03:47:31 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+a0NNhvAf+VT8poJdlCb3FEYishgk/9FXPnjUj/Ds8BaA==" Received: by 2002:a05:690e:2494:b0:5f3:b863:1e52 with SMTP id 956f58d0204a3-642f7680765ls2836026d50.0.-pod-prod-03-us; Mon, 24 Nov 2025 03:47:29 -0800 (PST) X-Received: by 2002:a05:690c:744a:b0:787:e10e:3e51 with SMTP id 00721157ae682-78a8b47a509mr86769247b3.6.1763984849054; Mon, 24 Nov 2025 03:47:29 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1763984849; cv=pass; d=google.com; s=arc-20240605; b=W2Do6T/tkbQRBic+sc24OJ4r5hTZ0uvJXPOKzMFzNEwnqBAxoPZKIcgYc5ZomGFe41 SgfJJc/WpLEnb30ZarOTf4JTTuZ23IMQ9po+KlPylc8nvC3/NLu8X6PRk7niT2GNFv8n bhSvobCll/cCeXmcmlrETg6t+jDp47NAtFpgWFm4QQnPrZQ89yCsCXJDzpz9gJtX+mjP FK95pcAX1ov+YdWfv5Ij+veNMKnVLOnA1liA2wb/UAMpLfO1LtQ0uutaWEKEUC/PUO49 nvw+aThN66xCojWjHO5g4PqAIKcT5tEsJIhgmM7WLbic4iw/8pmZrksG6Tz/N94IWqgV bXNw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=eELwxLZ8Ccv1VNPXZgZh33ZMUcEizbdWouahKyXZrNg=; fh=YgHcU2amhotomeH1Rv2VyUlgPjm8wpulXwrBvcHF4rI=; b=YB/v5rqC+vpcEAhQ5pdub91jOmcLsW8UtilIbgJ2w/QTlo2+o3WSGoiQL0rBoXOmOb 8/mvmh2Tdt2aYZz47CFAldh/gCUYk5Oxy77hDzsaDLFeiXdT0EnV0eRgmi3RjfiipeGw bQUHJDS/fgJv1zocuIdrP7G/t75IdGVb5Y3T+x0dlz/ixoA2R7nSdBfYy/H6FZ/NRuBG 6l/96Su66O8lsFk6XIfjPowJZzvnpgnLBdaxWMbsR76BGIn4OXYL4HizV/biBiz0IXE7 6CRP9a0uHwikFoV4XdP/EfW2SpbP4fegk9MZawvsKZceWFX5PKm/GPUH57bRZKZcvsqN QMnA==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=RogAhB9d; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from AS8PR04CU009.outbound.protection.outlook.com (mail-westeuropeazlp170110003.outbound.protection.outlook.com. [2a01:111:f403:c201::3]) by gmr-mx.google.com with ESMTPS id 00721157ae682-78a7988fc70si3176087b3.1.2025.11.24.03.47.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Nov 2025 03:47:29 -0800 (PST) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) client-ip=2a01:111:f403:c201::3; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=jb1cvGpyG8VY7P/mfYp2YywOXWFUjoOP+71L/vj6g2z+iMvuU/mbxYjANtBH2agy/8nN+1pA1TzwtQG+wO6Q405kUYVOmhVDs6hkYx+YPeCavEg4Ksfg5W4GJWsBJtxXF4rjNvM5PZgpZALZAqwEjqY0fuQwPfjNv/Vit9ALS0jZbhHZBLFUKsVz8loqfdudsLh8nv9s9yhou4rOLnJoW1Wl9F0185KHLAuKCMMpGRKbdI/pU9++kqEl+FjG3Hyw02pRXZ4skOSVETFSI1szJvGBIeg1MDeED8L17gzzqNaVZWzyJTcFsovQm8ONdqwS81vnSToD9G2gI+21xs7T8A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eELwxLZ8Ccv1VNPXZgZh33ZMUcEizbdWouahKyXZrNg=; b=KAAvf8Nk+9aRfPUO/RqZxnoeVck/BHyTClEWdOEdx8Kmg/IiLh6hjS56zs83BCRij19GPpyWPVGf3jhz6cBrYsjn9g9GzPKyKiSCKVMrFERcOcfkFC8ipd4+GoK5IcTQSiAnHyMtUEHwUV1hKq8mGmHURhpZ/GsuCpNefHwdUleJx4PKnEzzH1+XpbaWUVBH4CrOuJQuqcB1p+o0mPC89ogp5DP6LT8bL1NBMzGaDCOVv6nyvN00d/B7pTgmNAmOsxBuM+L+sH4sdvsUj4PrCYAHtsuMUpCpPWA7E5wxGjz1FCPIOtcZzCdGfosU1E6DbItM03H34CXsMWDfxfQb6Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) by PRAPR10MB5156.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:27a::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9343.17; Mon, 24 Nov 2025 11:47:26 +0000 Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe]) by DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe%4]) with mapi id 15.20.9343.016; Mon, 24 Nov 2025 11:47:26 +0000 X-Patchwork-Original-From: "'Felix Moessbauer' via isar-users" From: "MOESSBAUER, Felix" To: isar-users@googlegroups.com Cc: christoph.steiger@siemens.com, cedric.hombourger@siemens.com, jan.kiszka@siemens.com, quirin.gylstorff@siemens.com, Felix Moessbauer Subject: [PATCH v5 09/10] imager: create SBOM of IMAGER_BOM packages Date: Mon, 24 Nov 2025 12:46:37 +0100 Message-ID: <20251124114638.2238090-10-felix.moessbauer@siemens.com> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20251124114638.2238090-1-felix.moessbauer@siemens.com> References: <20251124114638.2238090-1-felix.moessbauer@siemens.com> X-ClientProxiedBy: SG2PR04CA0182.apcprd04.prod.outlook.com (2603:1096:4:14::20) To DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU0PR10MB6828:EE_|PRAPR10MB5156:EE_ X-MS-Office365-Filtering-Correlation-Id: ef42b090-1c8c-41d6-ff83-08de2b4f3d1c X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|376014|366016; X-Microsoft-Antispam-Message-Info: Lnji2mqoqcnzaODzW0Al2W5v53QeihpYvI/1P5XypcMtDbD1kJ4CjI/1bOasVdte95QzH/zSTHqJ9DWd/MhDLiwP7LfwLAgi8tJXcoj9tCNW58GTVkZiHHjru3ST9QiDrrRroYjIjrlxaTxUk8sUCTNW8FtTJ5+wEaZeJ6vpMSXlyQSmwBRH2r1CHcuiibchf8qY39MnnACGHiRUzOB5x0gzJfkyHyzjAhBQhpAR/OP6V+DtIBY6+sRLSX6CGesS8dHwfxsOPhsFDw6nT2SC1slXIjxL+GW7W+OFXpGiEu6ffJPZJnJxjEqL937ZeNL6G7zweKTiQcFdmRloz8wTXaV/rjjlM9kmD2KGN5YEgzTvHJxQg/ap840HZ95hqEwwqsSgs1qUEL+dK/ZwTDyDtpmNqmKoB2jRm4CZ6xPmEMcCm0D5nbuA/ODSWJrfZKkhVuVAEUqFOIVzR1BhzSJRUfbFYyQvuVI8YeoDtU31AsgIbD2ISxI+iHvlDhU//FKjzXDdJgrp3wW04xLjEL0EB54iDqGSgZKvL03IueftsAjnrYi1y5uXO8ZjziIAf0EpQ9/w/N4b4ZnJrxDM+7otczj2dk4GKiEvxdSxZtEA4i0phJbXL0cTy6fa8JuFfHUdGI2yjq65QHKXBelv6Q8AO8f3MMCVq+puItqg6prZQnIG5gHDWEipGIzwnX+pb8ymxYgBvl946fs/S4SmACFrOgklSg2UwZhH13/Hp0dT7jIw5rD3KkOxaPLsrkK2qssed+oHye7yEcUeru63R4MJyAE1yvPxaP/Fcp6OsR6kWL8LLczgbOSNpWtYJZzKKDacbcC0ED5h1Y/3BQFI8gLcvbkrcdFbS/7yLKMksBEn8E6Ox9ryu8F+94MEjSWjUrtoHpdkOHbuqew6GsP6SUH5dPiM3CAtpxDd8xYI48CnK8KgW5BS/qfcoI9oXNbsqJ9OkY9K2LmCYhQIvBKsU016v5uTelSqwwWxSgUGOlBcm1U3GTEGff4eIPP/v3BOu/uTj8Ct9f4g2HXLTzqFF8a2IwS5vs8oAIWsATQ+9QRwuu5B/HTDeS8umFw3Hv0IVnr28LZmJAdBu1kqh693CgZ3d2S0VJzsjkX8SRUbyx2QlV9I1S9AksBeIYXGZrH9wVfF8ei6cY5N1i9ZttrrERK24HHdIqdxg3q+lpO90AHJU6nJSivCEePEXWTDFjS4+2ahVdpnCgweF7Z6YK4HZ8yzaHmglV+s3iK45ATLfWFlHxlp2QIrlKq18BVoeFwbYWQ2LBiod6kd05AXKLzHk/KRhYrz0vxIuJkV4oSU9FD27vdgt4TAmc/hsYzduZYGDuJyGTl1oaCeKzXiP9z7AAkB6o9YqR2OYnlm3ul+tCsjBDCjGNe6cWHBBIlzUk+ADY+ucr1id6tfiBEg37x4BQr0dF02/CijPhwrLl9ftIAfrPX4zDsfj+PQO3VGnEyc5heF X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: zGe2Lgl+xsEN1ZJbAfxiAUsZsBYrjoLluyP2sRdigIYPT1x3n0EN7m8UfvoEnNo2qx5p7UsZRE/ljSryfk8zIgk9YjzGxko8zoNUlHEZHgJBUEOxnB1L0P9KETLhT4DmFPBsqp/Qxl2Y5DVG9/ezUz2ZblwPZlXhM77r/GgNwBNrx3dCitWtJpGSnSq4CP51Sj8n2YNyU0Rt10zh6UBQfZKTpq03QVjZ4vvayDVInhYFlVqWEdx17YxxCHWnPxyDZnfsMFeco0ZsA61DYswsiFHa/7A9Pecqf92aXS2zYFmXfLpPLFZI5YRF0k5WKWs+6574IpND5W/eih6rTAIzyL9SfQziBXOmEBR917YDQgqci0RO52TspiPHZpU0JAzrT/O85w1ipugN1f4idBFe5sFjlw5FznLAuqoMw0WcIz2BBHxZvaHuBidOrk4HSd/yaYFtkA9J2FyiC9MwCFJ4Kk70/ZPdD+FuQx8evTBiD+nK7JjxUCsWmfUofF9Oak6nMel4nkfKaJ7XryYeh9StQiBiFTX/YCcTDswzl39nW39mZpQJyfq8qAAG6MF+dADGhf2x1gyaHQA4J1UVWlq71OkidP6uNFhApGHVmfT3rk3wVtI3YxyYBKufMkwk70ofHHwmFm9TTJHEVNL8dbJsz6y0g5HgjVH20Mx23PnNcTGZKMJ3NG516fpcYgFnV8FXLbBAL6x171ys+MSwaOLa41MX84t9MtKXwOsLaO65h+BU3dk+IOHuCkojDxHKFw+Nc6J4QNImdE32E1v8bV+QXDngYfvvPOtRTOVMTU3KtVIgxrkRV4Z7ZqNDu/MMP2JxcjFt0PLOC476Vif2QHdXRLmQ54RlTaf6usgBabrTaz/SCP9THjs7jBwXMIprW9WSPc3Q7WCXUIW08iec/Z/Z6Hxg6gqgHPpWNPhw+XpNdtUYam2iprJo/WWInE1AzXgzoqXCt3GV/eg6kNibzeg1zkBDaZEresShzM6iSXuvfXzJ49AJCtTq6oaAKbscz+7ndMUB+itrxN3THeXITzT5jWS43WzBTB7ZVAS9w5pyNdIc0rDIBb0Lu1qLqsAPj6rQX0U8Pf7KQ9voyIZCcJu1hTBpX+uprA6N/hgEvdQ08ZTS3aLn7uDeoJUV4c4OjgMs/zqR7dIiEGG07RzGaCFmbKbNBERW3/brb/Ae7//Anh9w0Z6Dp60VfW94ebgj9KAFVbYLBgN/jGMcQrSgeFbZHVFkZRk8Klb2dm7gbwYmRRkpIf6Gv7l0O37jbh39GgigYDin3XYNMzh53KVtcyfIwpskpQDSDjv2Oe5etI2wP1jSJNxnF9v5o4OAAS9PaOdeWyXfEUB9iLJ35CfVF1ctWP1xcKFBKfMNLgr+oWUf/mVSDsR2onA6jpS13CB3Gx+Rv7Xi1DjdDZMNHRutMYJbxceXDuWan8R+d42U0bEUEhRHwjg+m68dtY/+i3VOPjV2TxYCxNHgVNz33XblObmBr8IJRnF1+q3M/enTdlpcSVg+f7uzmMSa66sGm9nIbvRgoI1ir3HUSpiCrbvBtAauf0uGn+exziqPs/vNdL8NxN4D8bpQsURQXDU3mdKowO06RkIHE4EJNkOevvWJHFulQg== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: ef42b090-1c8c-41d6-ff83-08de2b4f3d1c X-MS-Exchange-CrossTenant-AuthSource: DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 Nov 2025 11:47:26.4050 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: uX09xfTQb6jzF0CAEnIg8rZr5MWE+v2euqZUeAM6s/4LSXwUImwErfQjRPIHIEhJ7IskaqKYxZzsmxwwYA9h90r/uQnclpcwXbEep5ujkTs= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PRAPR10MB5156 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=RogAhB9d; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Felix Moessbauer Reply-To: Felix Moessbauer Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= This uses the same interface as the .manifest file, but adds the packagse to an SBOM. Signed-off-by: Felix Moessbauer --- meta/classes/image-tools-extension.bbclass | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/meta/classes/image-tools-extension.bbclass b/meta/classes/image-tools-extension.bbclass index 2027effb..95f003d0 100644 --- a/meta/classes/image-tools-extension.bbclass +++ b/meta/classes/image-tools-extension.bbclass @@ -73,6 +73,8 @@ EOAPT schroot -r -c ${session_id} -d / -- \ dpkg-query -W -f='${source:Package}|${source:Version}|${Package}:${Architecture}|${Version}\n' ${local_bom} > \ ${WORKDIR}/imager.manifest + + ${@bb.utils.contains('ROOTFS_FEATURES', 'generate-sbom', 'generate_imager_sbom', '', d)} fi schroot -e -c ${session_id} @@ -80,3 +82,23 @@ EOAPT remove_mounts schroot_delete_configs } + +generate_imager_sbom() { + TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH}) + sbom_document_uuid="${@d.getVar('SBOM_DOCUMENT_UUID') or generate_document_uuid(d, False)}" + bwrap \ + --unshare-user \ + --unshare-pid \ + --bind ${SBOM_CHROOT} / \ + --bind $schroot_dir /mnt/rootfs \ + --bind ${WORKDIR} /mnt/deploy-dir \ + -- debsbom -vv generate ${SBOM_DEBSBOM_TYPE_ARGS} \ + --from-pkglist -r /mnt/rootfs -o /mnt/deploy-dir/imager \ + --distro-name '${SBOM_DISTRO_NAME}-Imager' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \ + --distro-version '${SBOM_DISTRO_VERSION}' --distro-arch '${DISTRO_ARCH}' \ + --base-distro-vendor '${SBOM_BASE_DISTRO_VENDOR}' \ + --cdx-serialnumber $sbom_document_uuid \ + --spdx-namespace '${SBOM_SPDX_NAMESPACE_PREFIX}'-$sbom_document_uuid \ + --timestamp $TIMESTAMP \ + < ${WORKDIR}/imager.manifest +}