| Message ID | 20260121150719.2719579-7-felix.moessbauer@siemens.com |
|---|---|
| State | Under Review |
| Headers | show
Return-Path: <isar-users+bncBCYIZ4M3XAKRBRWXYPFQMGQERGBGICQ@googlegroups.com>
Received: from shymkent.ilbers.de ([unix socket])
by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA;
Wed, 21 Jan 2026 16:08:12 +0100
X-Sieve: CMU Sieve 2.4
Received: from mail-ot1-f57.google.com (mail-ot1-f57.google.com
[209.85.210.57])
by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id
60LF7uJE004056
(version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT)
for <iupwgm@isar-build.org>; Wed, 21 Jan 2026 16:07:57 +0100
Received: by mail-ot1-f57.google.com with SMTP id
46e09a7af769-7cfd731693esf15360959a34.3
for <iupwgm@isar-build.org>; Wed, 21 Jan 2026 07:07:57 -0800 (PST)
ARC-Seal: i=3; a=rsa-sha256; t=1769008071; cv=pass;
d=google.com; s=arc-20240605;
b=dSVvw1qq1ljioG2T871FbXqLuEKcxXVAzAyWn6MjAXV3GicLYq+6nwzkkV4pLz8+m7
93rya9MUbEQQxyqDGAd/ekEmmAWmG9hdnhplklnS74GO1Qp9KkbPmeZckuNI+9f/QikM
CDvmK3SUWHQw+5oXMFRexOZTLbN+UXg2JUVu0+RUHxC2lAXa3nZKgWfQBK2jdFUGqOvV
Hj/UoMjFA92NQMxAAlCrVG5I2Bbii92+3qvI2W/bHHzkbgpgGuCdkmCyFGey1skvV6/J
TTJwK6Mp2+CUE9ywXm7VKsejobiWB0hMFG3q94YqElzkImrv+Ro6pRARgCCYj9n+T+Up
edhA==
ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:reply-to:mime-version:references
:in-reply-to:message-id:date:subject:cc:to:from:dkim-signature;
bh=kCZZDNenFlklHSUsUHAdViNUybBc6q+wPcc/ysJGzxI=;
fh=lNGUt/AI28vMo59ChXSnoXT+wsqIGm1FMZmqe8JH62c=;
b=I6FEZl6fGG37/g5yBxeQ6dyVtivcvnvgpkX3Uhe9sYBN1csdtztcCZLO+mVglno9zE
gzHIb/XkH0KqvwloSOFzgr1dzJ5Bof2eJtmWXmAsmb1ycb7oENJtLLQfy3orX3vA8lrL
VfjCu4xCTIaOa60Y4Pt6VNYk/4Y6FOBrFoscKg5gEHJekEwLfcZL92TF8FrSSS1x1OSI
GCi7vB3Cb0uU7EefchTW/axQjiFsKZ0EsKOJJU2NjCrHqe/NYH9mnBU5Etn/80CnF+EC
wRaYfXt9MX4CK6RDotyN39Kg96j4OjclwhFT1jHWPzv+etLemUlLb/UVpzcAy3K3uWUD
jXbg==;
darn=isar-build.org
ARC-Authentication-Results: i=3; gmr-mx.google.com;
dkim=pass header.i=@siemens.com header.s=selector2 header.b=tiHbErEN;
arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass
dkdomain=siemens.com dmarc=pass fromdomain=siemens.com);
spf=pass (google.com: domain of felix.moessbauer@siemens.com designates
2a01:111:f403:c202::7 as permitted sender)
smtp.mailfrom=felix.moessbauer@siemens.com;
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=googlegroups.com; s=20230601; t=1769008071; x=1769612871;
darn=isar-build.org;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:reply-to
:x-original-authentication-results:x-original-sender:mime-version
:references:in-reply-to:message-id:date:subject:cc:to:from:from:to
:cc:subject:date:message-id:reply-to;
bh=kCZZDNenFlklHSUsUHAdViNUybBc6q+wPcc/ysJGzxI=;
b=f5ge9URcPsnASqrY1G4ftoxXdTCPIs8Iq3awtyBroUP6aDVUxfipvE/L2eUQSE4tZJ
BKHVXhi+hpL3A+OFa8mquNPg9CpQgGy8kozmfLZLUhVNKlEYhsPvwdXCnzQ79pNWxJkD
kVS0DPD2P+sjRtYyfahqHBimppqWnytuVGDuiZ/prMH6FB6P2xjV+QyIhxViu9gqQ92S
kFtrYIESR2aJ4N+5cJALdZxL4SIDmUHdfnGSJ3EG8mOrm3LlEpYYl8MNcElkn55hFFlA
lmCxVlv+3Z+o4hjg0jYiQya69+GoSqZdMJ84AyGAzbnddMo97HXe7NIP84jJGUbB5RQw
0nqQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1769008071; x=1769612871;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to
:x-original-authentication-results:x-original-sender:mime-version
:references:in-reply-to:message-id:date:subject:cc:to:from
:x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id
:reply-to;
bh=kCZZDNenFlklHSUsUHAdViNUybBc6q+wPcc/ysJGzxI=;
b=Y5zEyWh29RCbjO1cBNzpP7CeqQl10iZIi25q8A01Tkbqtj6n38oAJq4OngiSs8Kz2V
N3KMJRpJPn3EILS71cDWbDJQp8FFeY6f4NVU6TsTQtq2ZWBihBVCOmesVNejWUf2idtP
7VIDyGn2hX4Gux6mFuYrteAZxoDC1mSWvEf1zTicW8T0pqOtzbUEEfHIIxpEpOrAjNWJ
N9Vs/G0EMz0H8nMcLLCogVzZBozrdZDfiZ7B91tqYaGIIfpnjjBJ3O50aX0JJh8JlaG8
SOs5W1vqQHQQ3C1c4dWiyCKXyFtUAMqwf5w2iTLz5YSeyaocbSlQ1J4h9hmsnr2gRnb4
fg5g==
X-Forwarded-Encrypted: i=3;
AJvYcCW0mBnKjiF8J3173/ISDZxoh/wlOlE57/dzngoq9YsKRrMonWH8ZxV1PkRpXHu72aarvQgPd4Y=@isar-build.org
X-Gm-Message-State: AOJu0YwFcdr16+ep77Qc8bpX/ea1RGQ+MeWf4F0zyNEXBxnlOJmUqUCL
I2W2LjmaeX1xxJN1JXwYTMOeFnCD6vy0DSJ3+kwI87NO91amB7Khkkrg
X-Received: by 2002:a05:6820:1993:b0:661:1c57:1b40 with SMTP id
006d021491bc7-662b00ecb22mr2057682eaf.63.1769008070924;
Wed, 21 Jan 2026 07:07:50 -0800 (PST)
X-BeenThere: isar-users@googlegroups.com;
h="AV1CL+Heo2CuoC8eleDW8ytlVYrXKGQ+xDOxluRztseymSuGxw=="
Received: by 2002:a05:6871:6803:b0:3ff:ac5f:8bfc with SMTP id
586e51a60fabf-40428a3f345ls2652870fac.1.-pod-prod-09-us; Wed, 21 Jan 2026
07:07:49 -0800 (PST)
X-Received: by 2002:a05:6870:b009:b0:3f9:d104:bbb0 with SMTP id
586e51a60fabf-40846c64aa0mr2584503fac.25.1769008069784;
Wed, 21 Jan 2026 07:07:49 -0800 (PST)
ARC-Seal: i=2; a=rsa-sha256; t=1769008069; cv=pass;
d=google.com; s=arc-20240605;
b=F6TUk744/HZfwX//A91EUspM+qS4u2rhGgDAmzd0xzfUON+uaPoBnvW+8wkFpzXhDj
pQ7xsUSbzkiEzLviP1M0wnhAoJa8143tktJrlr8sCy3dCEflbqfbz9HGz0KsAlF5z7xH
5u7WN1Hsj6gBZ8x60MkDXFgKErKHdDFK0Zyx8P7n7a9YVsw7IkHNGqUuEgvXQJeqNY3N
httYB1y0cfblBbdc1WCKBXBut61VDHsTwQp3+H7cdSf+R3WlExK+TRaI265v+UItqUjt
xjVFx5GJN7VczKsivREglZ2gnsuru6RGsmXxg80ZFrVgwKOG9YQq+iV2p1muxWDmCybn
ot5w==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=mime-version:content-transfer-encoding:references:in-reply-to
:message-id:date:subject:cc:to:from:dkim-signature;
bh=HnVVAtuE6nYSbHsa3xEkP6O/ywR6cPRsMekx2fzlqzY=;
fh=3TZ2kfKzTV0uAG2uKD8NJHxpu4kGHzyonq8tLR1Voro=;
b=L8CKR/R0cKix2eZcokU39hXrtd2yrZ/2hBC1t7U6uEDLFNsa4zYFvXDI6WC2nAU+mL
vkuEXa5MrajsHNvvPyrnb2sOAOSQDjfuOIK1DcZK77RcGZtgYX13PWZh+oehkBHjQh1x
b6d4c5CmJqZ7V8atIMcXza8Bl9cqNbB+/S8G/zPrL0KNbewPxgnEIdBVx5DL7rSgtFe3
Tgn+cST/O0vTCmbBvCnmgCF5JU5KOU+WQM/gAqkn1gZHC4dmhcuwo58eM7dKk5Nix5xn
As9GdFxMibR4y4jN56SQUSTx8NWCK1JyX9OxpG7jz92gmxwAQ+5FVVT1uI/y82k0imJ1
wQqw==;
dara=google.com
ARC-Authentication-Results: i=2; gmr-mx.google.com;
dkim=pass header.i=@siemens.com header.s=selector2 header.b=tiHbErEN;
arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass
dkdomain=siemens.com dmarc=pass fromdomain=siemens.com);
spf=pass (google.com: domain of felix.moessbauer@siemens.com designates
2a01:111:f403:c202::7 as permitted sender)
smtp.mailfrom=felix.moessbauer@siemens.com;
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com
Received: from GVXPR05CU001.outbound.protection.outlook.com
(mail-swedencentralazlp170130007.outbound.protection.outlook.com.
[2a01:111:f403:c202::7])
by gmr-mx.google.com with ESMTPS id
586e51a60fabf-4044bc8c805si431656fac.3.2026.01.21.07.07.49
for <isar-users@googlegroups.com>
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Wed, 21 Jan 2026 07:07:49 -0800 (PST)
Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com
designates 2a01:111:f403:c202::7 as permitted sender)
client-ip=2a01:111:f403:c202::7;
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;
b=gMNxwe9p35kcW64KhnVTYmLav0uACAc8GknaMFXp5HsuvocbdgurkcoD8kzjoHahcuZlriEGYllWOOyCg0CCXY/RriTRnmwS3fi91DnHwJEqwhniW22nvVIL2FhdT5eEsIdxOELEHFaHuPFG/qzZt6nxvwdXH3tnJlSuF4XDmL8/RzpIub87wf6RC5WZ6KrtNqoqzug55qVvFiZjKbAKzvu57abkm94b6wmoPzOURbHdDAPgASKVnBJOWt1YJ3GyShRzqqJhvoCxyshitRpx8B2lk5kxTU98PWZxrbMKRoFShjAS1zLy9D94wNhyj1quK46qB0k60uj2G2H1RaQxEA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector10001;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=HnVVAtuE6nYSbHsa3xEkP6O/ywR6cPRsMekx2fzlqzY=;
b=NtI6mbPNCYiLuJzFpy1BvDupqfbU8xDMV3Ba3gfH/o/Rv+FCw4yXLq/7MRsZz1JlXYlqPs7/GM0P0jGUk25kTNBqvKM0zdOOFOcxZhJLEdEQzdT/C9iYtngHzTFr2cAGHvauANfsFBfQpDfp5Ai33v+8eWdIRJP/pFznTcs+7YbhWX3ejGkT64Q1srn3ydUnJRzFo+PEYWZTnUYP+u9LAA5aZlIpq3ijey3ZhC9PaPLvIsYGWxL2BueN6Cq3yCroGQHRlQVdBy5ShBKrwxRnetRBPQxj5rimyeLYwXMVi0TvQJYoq1BRgM8xvmE/w5I8V8BKPCSAxbJNHKHksm2ifQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com;
dkim=pass header.d=siemens.com; arc=none
Received: from AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:5f6::12)
by VE1PR10MB3806.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:800:148::15) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9542.9; Wed, 21 Jan
2026 15:07:46 +0000
Received: from AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM
([fe80::349d:731e:a849:b4a5]) by AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM
([fe80::349d:731e:a849:b4a5%6]) with mapi id 15.20.9542.008; Wed, 21 Jan 2026
15:07:46 +0000
From: "'Felix Moessbauer' via isar-users" <isar-users@googlegroups.com>
To: isar-users@googlegroups.com
Cc: christoph.steiger@siemens.com, cedric.hombourger@siemens.com,
jan.kiszka@siemens.com, quirin.gylstorff@siemens.com,
stefan-koch@siemens.com,
Felix Moessbauer <felix.moessbauer@siemens.com>
Subject: [PATCH v7 6/7] imager: create SBOM of IMAGER_BOM packages
Date: Wed, 21 Jan 2026 16:07:18 +0100
Message-ID: <20260121150719.2719579-7-felix.moessbauer@siemens.com>
X-Mailer: git-send-email 2.51.0
In-Reply-To: <20260121150719.2719579-1-felix.moessbauer@siemens.com>
References: <20260121150719.2719579-1-felix.moessbauer@siemens.com>
Content-Type: text/plain; charset="UTF-8"
X-ClientProxiedBy: CH2PR17CA0026.namprd17.prod.outlook.com
(2603:10b6:610:53::36) To AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM
(2603:10a6:20b:5f6::12)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: AS2PR10MB6823:EE_|VE1PR10MB3806:EE_
X-MS-Office365-Filtering-Correlation-Id: 975760c3-bdbf-46dc-4d64-08de58fed5a8
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014;
X-Microsoft-Antispam-Message-Info:
ReOT6/w0Bq3P9CCLkUKnaBAcTWcGp83R6PXMhRLszhmuhQ0txzYtCEjvLfrn5uugx/9DC+k54VhD9i0a5D4kJYTDYYnO9ohlGfXdFHW3UdIgUW68mRtvTqjLdUJ5vY2FXKWZn4UrfuJ+XoULMNMCyIaGJGOMEsnUHTZoj+ZBCNPL00NxWosEiDTbOHuaHE1uUEQSKdGILJqCE0RYs3WG+0R7HS/9hVs8gGhmzVD/D4nI8xOLExXhMDE4i7tGUfOPt8pJrwrOVPbpDr9bfnkTdpjdCOjVG0sn/EKzDozGQKE+Jm183oFB0LrBdpzk+B0iFm84URdsV3OZHBogtJLgrBZsSLpok/4+RmU0r8Ci9ce2cADRyYegYg/6v3mH+YKamU8MGbLixIoYhJxwJ/y4mbbWI1eSD1EtcTylXX9Meq1MGVrbKwcNQBTSDhp32Chaw614/iq0uW7JM6QYHLTYGNiDcd2Ca/KBnG2vu2OshmQCfbqTJ+erzIxKhtpZnFgnMKck7bSn1fCmsBAmDrrX+YnwZZvBho6GX8FkmO3D7wj7PqHL58UQR6+qwK5iYQMAYL1ro0OCgCrbNpYJiPipgoxfBrrJdziFrMctopNl1b2s1VTviWn9Ce8aTUZj0D+YG68BaCVgOxf5nuCBGhbDhRdGuS7he444Ip3nhIA4y724iAChkM8jxKolzIAtinW6CijHrRZAHeCj758zRmvNKR/PwXX6hme6uhrR8q0haXlTOZY0zftFJOCEBV/dV1Xh1wLevxtXG6pyTWgFOPTwEBLlcVSJ2e88wjxxOFpC2rwYDOauQK58TPCyL7K0NnLqWyQQjHbwveUqVDnC6iZlGQzQ5HJ2LZjXtFoxtYLHakXWaQK9qhI1aYpGgJM/7a4JjUIoXUyF49VBIK+ta+D3+ptEOEb0KATLXqowcWHrjJF1Jqm2cTyHSgk5XXcuyxK7san2AupPHUhaVHqhu5h5IZmrqMZB2mzfbNOyPDxhTCNW87X9cqL+figlLvtKp71ONfjg8WcEgFH7Ls8ViLiAbkSqE/eI1/IIDE8sUzAu+6PdlYeQyFJUAEJSy6cc5pzGo6O1JnJtWzCmsr1EUTjBfGDpei/0j2mcTKcci2GkLW5JXFhhHMK0SjdX8oAYBuXKqmT/t1fNz7l4YVMf6v41OI4xVudZ+MGDZ9XPnpZZqnBMyT37oLEOKnzaWLeigjdxLIOfT/4GBke2rfq/9raSBti4yHAtZTYZllC1ZP4qVob7r2OaNmtYulpbZcSXMkhLr8WLoO3NYD7noLZ/PAgUaNVGi6vwQFJVBnrttwXa0WouYqfbgEkjetAG+xQz7YKG8Mw7KUwHMc4FyCMpldWujMYCQqQrot1D8NkP3jedOF6ZAUy3WGaipwiYdtwoMIT9Zd4QEl1POHK4i4M2QFwHmKHfXE/ikEeb15pIosXQgYjqFL8BdijigBwemlKtudJaGq0xJm8XJueYcH9l5s+298ngy0RpxVkJZFkfHqarn1LtO+ZXDEDyp9muoPH5RxzQ4JmNt3n7dfiMps4P8NH1bUWkfvRCP43xx2s/laVSfvw=
X-Forefront-Antispam-Report:
CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014);DIR:OUT;SFP:1101;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0:
G0YnVnOw+Zhhd6vn6E73zbTgXjMed3+1E82GuS5PxPmqbJbmjZ2xyQfLKw0IYyx6wsZsYlY9JXWlS20XrZweLdzUINXjYWvSXsbqcW5irVSr9fnX2WIu+7XXrlMuDajPWMX4JX/7H57/DxXyWGdcfB7HQcbiZTf274Ixo4OPirv4A2Fw9396CcjXQNf9bJgv8y6UD19yVi6EpWoQiuL+7f3moKTvuf70lgnX3OG/opDTB23NlnAvuSSQzJpgZ1W8Juc9IgfZe/jrpI3uzL9UlBYcK0pb7/KdoKX/ESXX2WFvG+M8n/5Mk46yBVkZrIucHhtPur/WpO7/z/e33mzv2Gdq7x1LTCIdCLPs7FOGya/dQmEPgorynHW9j03xXGRyxviIU5nNO0OKLi/dR6QXFQTc/2QITF8S9BvfQFSBa+dmfwAy7KVKZQD+T+Ntp0ArhnmPoM4NkA/zTV8DTbTAvpZJLJJTxWV8AyExmOuEyBus34hR9WOT9sbQ4tgHDqssQhxmYkRtVe0FqWxfOxUkNHVCI+BAnfWZ1xuHYb5O4NsEptF3+9oJaoXFjX+F0ttoC2BR9ppjgvwUNZHjefwD0b10E42PpwSMObubHJMcCeJzZGTbmwoNjbi7b1Vz0nnvb/QCGGtWB8DPcu2P0nfldZwcfHbk9pPh0zSoWqnIn4eSvfrC/0iyWYc7CRO+/eKZq4ORMr3XU829WdQaU36rDW8V90WqVpNLcaRse1Iw/xBUj3koAd1GEP196AeTq0jNNL3iUXcmd2fp/HiE9yrLHsA7gZ0RUHi5IDIQZJzxR05S3mqWOGXl/NE0H/URy92zPY7yxQgUwZ6SnoZGA4ONiHszRUz3wn21eOeme7HXKxvEIUisuzxiWOF0BbW62/yrmnCriIdAlxa5Wb904oIeXuLoCNe7yIbN/1FBHB+ALCqipswlG4PxqIf3ttMpSrpvAtx3zVPxy065mQZ1kVvvGO8v29ANApfWvl80ULDL9NSW/r+eFCAoOzNo6azKDQrGBdBvkvOwictZzBrWjm6r9vnX7HReqQBcbjybYvGMfNasCW44HfFUzgxNXKbNo840UurQMGcCzycf4tvIwG+BuQYrOY8kRt6KxWkqqUJzAFQ5iIIRMGvjdyEkKkyAWSLXzoC2e+7nAKm0fXVewnulltWCD6sUMJrYfM6gsXBzOM7nBlJZf/TlIbSG6B2i4Tq+lzji4+8YwUxOf9hGlUqK57Xsp9EsWaIlmbAO1YUBs1KBBvTO9vgNvrkn6KyOfLSy4oqCtpFJeRVn4WdtMINz1AltLm8wIh6fJeSJEgn6pa9/eMgCY/sgKjj7ajt4KRBg7n1IgMqL46Zy7UQkK/Dh1ztT6b09U1g7wTMxKNlhAmfiH+yy7CCq4tRQW0hPjW6KVxZKThIqI2nNiQ4Yx1gp65761RObSRF5PT8d2H9XZOT7Tt+J1FVTJw8m0nkGI0AIlOjRLMU+DPfWiGbavHa7S4LjRV0bbcyWaDx2UPQoomdMEe4J5o9CtkPEReXRNsAzvzUIGfe68B5endcYM9BCyrN9hvbQD7uhwdY7HR1+HjCNG5DDAlSsbEALoyCV2X72cKpUFIyGt+4J/01qy1CD8CrVEBUvDsjXyJEVjyc9aG2H5GxCGAr8Avy8TvRg3qEIj7pHCDmOpiO6QWQpYQVHx3QN+0gRjcCRE6CLjCQjIXilgvHRtuu9mqoUk04Uh2I18M5ECgoC+xas5j1cwQFUJqUGGJrtBVUBRFBC3PmVqcg=
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-Network-Message-Id:
975760c3-bdbf-46dc-4d64-08de58fed5a8
X-MS-Exchange-CrossTenant-AuthSource: AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Jan 2026 15:07:46.6716
(UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName:
Gk3aDPcu4fQd20r4jSOn8lra0G2VJIxCNG3dQWVXjpwu33cwU45fbYUW4aur0YhJIPTUuyRJCMTOjw6gJXqniaZrMoLc//j+FhjLX3JhRcE=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VE1PR10MB3806
X-Original-Sender: felix.moessbauer@siemens.com
X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass
header.i=@siemens.com header.s=selector2 header.b=tiHbErEN; arc=pass
(i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass
fromdomain=siemens.com); spf=pass (google.com: domain of
felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted
sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass
(p=REJECT sp=REJECT dis=NONE) header.from=siemens.com
X-Original-From: Felix Moessbauer <felix.moessbauer@siemens.com>
Reply-To: Felix Moessbauer <felix.moessbauer@siemens.com>
Precedence: list
Mailing-list: list isar-users@googlegroups.com;
contact isar-users+owners@googlegroups.com
List-ID: <isar-users.googlegroups.com>
X-Spam-Checked-In-Group: isar-users@googlegroups.com
X-Google-Group-Id: 914930254986
List-Post: <https://groups.google.com/group/isar-users/post>,
<mailto:isar-users@googlegroups.com>
List-Help: <https://groups.google.com/support/>,
<mailto:isar-users+help@googlegroups.com>
List-Archive: <https://groups.google.com/group/isar-users
List-Subscribe: <https://groups.google.com/group/isar-users/subscribe>,
<mailto:isar-users+subscribe@googlegroups.com>
List-Unsubscribe:
<mailto:googlegroups-manage+914930254986+unsubscribe@googlegroups.com>,
<https://groups.google.com/group/isar-users/subscribe>
X-Spam-Status: No, score=-1.2 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED,
DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI,SPF_PASS,
T_SPF_HELO_TEMPERROR autolearn=unavailable autolearn_force=no
version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de
X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?=
|
| Series |
Add SBOM generation with debsbom
|
expand
|
diff --git a/meta/classes-recipe/image-tools-extension.bbclass b/meta/classes-recipe/image-tools-extension.bbclass index 2027effb..b0f25a69 100644 --- a/meta/classes-recipe/image-tools-extension.bbclass +++ b/meta/classes-recipe/image-tools-extension.bbclass @@ -73,6 +73,8 @@ EOAPT schroot -r -c ${session_id} -d / -- \ dpkg-query -W -f='${source:Package}|${source:Version}|${Package}:${Architecture}|${Version}\n' ${local_bom} > \ ${WORKDIR}/imager.manifest + + ${@bb.utils.contains('ROOTFS_FEATURES', 'generate-sbom', 'generate_imager_sbom', '', d)} fi schroot -e -c ${session_id} @@ -80,3 +82,23 @@ EOAPT remove_mounts schroot_delete_configs } + +generate_imager_sbom() { + TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH}) + sbom_document_uuid="${@d.getVar('SBOM_DOCUMENT_UUID') or generate_document_uuid(d, False)}" + bwrap \ + --unshare-user \ + --unshare-pid \ + --bind ${SBOM_CHROOT} / \ + --bind $schroot_dir /mnt/rootfs \ + --bind ${WORKDIR} /mnt/deploy-dir \ + -- debsbom -vv generate ${SBOM_DEBSBOM_TYPE_ARGS} \ + --from-pkglist -r /mnt/rootfs -o /mnt/deploy-dir/imager \ + --distro-name '${SBOM_DISTRO_NAME}-Imager' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \ + --distro-version '${SBOM_DISTRO_VERSION}' --distro-arch '${DISTRO_ARCH}' \ + --base-distro-vendor '${SBOM_BASE_DISTRO_VENDOR}' \ + --cdx-serialnumber $sbom_document_uuid \ + --spdx-namespace '${SBOM_SPDX_NAMESPACE_PREFIX}'-$sbom_document_uuid \ + --timestamp $TIMESTAMP ${SBOM_DEBSBOM_EXTRA_ARGS} \ + < ${WORKDIR}/imager.manifest +}
This uses the same interface as the .manifest file, but adds the packagse to an SBOM. Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com> --- .../image-tools-extension.bbclass | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+)