Skip to content

Retroactive CycloneDX SBOM for 1.5.0 (not for merging) - #6

Closed
jadamcrain wants to merge 1 commit into
mainfrom
retro-sbom-1.5.0
Closed

jadamcrain wants to merge 1 commit into
mainfrom
retro-sbom-1.5.0

Conversation

@jadamcrain

Copy link
Copy Markdown
Member

Not for merging: this branch only runs a one-off workflow that produces a CycloneDX SBOM for the already-published 1.5.0 release, which will then be attached to that release. The published .nupkg is not changed.

How

The 1.5.0 release run's build logs are no longer available, so the workflow reproduces the release builds: rodbus 1.5.0 with the release's exact arguments (-p rodbus-ffi --target <t> --no-default-features --features tls, cross for Linux, the same MUSL flags), recording each build's log and cargo tree outputs, then runs bom-tools 0.3.0. The crate set is fixed by the tag's Cargo.lock, the features and the targets, so it matches the shipped binaries. The allow list is rodbus's migrated allowed.json (stepfunc/rodbus#201, pinned commit).

The result is checked against the third-party-licenses.txt published with 1.5.0, which was produced from the original release build logs.

@jadamcrain

Copy link
Copy Markdown
Member Author

Done: the SBOM this produced is attached to the release (see the release assets). Closing without merging, as intended; this PR and its run remain the record of how the SBOM was generated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant