diff --git a/.github/workflows/retro-sbom.yml b/.github/workflows/retro-sbom.yml new file mode 100644 index 0000000..a458204 --- /dev/null +++ b/.github/workflows/retro-sbom.yml @@ -0,0 +1,96 @@ +# One-off: a CycloneDX SBOM for the already-published 1.5.0 release. +# +# The 1.5.0 release run's build logs are no longer available, so this reproduces the release +# builds: rodbus 1.5.0 with the release's exact arguments, on the same hosts, recording the +# build log and the two `cargo tree` outputs of each build. The crate set is fixed by the tag's +# Cargo.lock, the features and the targets, so it matches the shipped binaries. +name: Retroactive SBOM (1.5.0) +on: + pull_request: +permissions: + contents: read +env: + RODBUS_REF: "1.5.0" + # rodbus with the allowed.json migrated for bom-tools 0.3.0 (stepfunc/rodbus#201) + CONFIG_COMMIT: e213fea869c48ce7c3972230e4c79f42dd449aa2 +jobs: + evidence: + env: + # as in the release build: MUSL cdylibs link MUSL libc dynamically + CARGO_TARGET_X86_64_UNKNOWN_LINUX_MUSL_RUSTFLAGS: "-C target-feature=-crt-static" + CARGO_TARGET_AARCH64_UNKNOWN_LINUX_MUSL_RUSTFLAGS: "-C target-feature=-crt-static" + CARGO_TARGET_ARM_UNKNOWN_LINUX_MUSLEABIHF_RUSTFLAGS: "-C target-feature=-crt-static" + strategy: + fail-fast: false + matrix: + include: + - { runner: windows-latest, build: cargo, target: x86_64-pc-windows-msvc } + - { runner: ubuntu-latest, build: cross, target: arm-unknown-linux-gnueabihf } + - { runner: ubuntu-latest, build: cross, target: aarch64-unknown-linux-gnu } + - { runner: ubuntu-latest, build: cross, target: x86_64-unknown-linux-gnu } + - { runner: ubuntu-latest, build: cross, target: aarch64-unknown-linux-musl } + - { runner: ubuntu-latest, build: cross, target: x86_64-unknown-linux-musl } + - { runner: ubuntu-latest, build: cross, target: arm-unknown-linux-musleabihf } + runs-on: ${{ matrix.runner }} + steps: + - name: Checkout rodbus + uses: actions/checkout@v6 + with: + repository: stepfunc/rodbus + ref: ${{ env.RODBUS_REF }} + - name: Install Rust + uses: dtolnay/rust-toolchain@stable + with: + targets: ${{ matrix.target }} + - name: Install Rust Cross + if: matrix.build == 'cross' + run: cargo install cross + - name: Build and record the evidence with the release's arguments + shell: bash + run: | + out=evidence/ffi/${{ matrix.target }} + mkdir -p $out + args=(-p rodbus-ffi --target ${{ matrix.target }} --no-default-features --features tls --locked) + format=(--prefix depth --color never --format '{p}|{f}') + ${{ matrix.build }} build --release "${args[@]}" + ${{ matrix.build }} build --release "${args[@]}" --message-format json > $out/build.json + cargo tree "${args[@]}" -e normal,build "${format[@]}" > $out/tree.txt + cargo tree "${args[@]}" -e normal,no-proc-macro "${format[@]}" > $out/runtime-tree.txt + - name: Upload the evidence + uses: actions/upload-artifact@v6 + with: + name: evidence-${{ matrix.target }} + path: evidence + sbom: + needs: [evidence] + runs-on: ubuntu-latest + steps: + - name: Checkout rodbus + uses: actions/checkout@v6 + with: + repository: stepfunc/rodbus + ref: ${{ env.RODBUS_REF }} + - name: Install Rust + uses: dtolnay/rust-toolchain@stable + - name: Download the evidence + uses: actions/download-artifact@v7 + with: + pattern: evidence-* + path: evidence + merge-multiple: true + - name: Install bom-tools + run: cargo install --locked --git https://github.com/stepfunc/bom-tools.git --tag 0.3.0 + - name: Create the SBOM + run: | + ls evidence/ffi/*/build.json | wc -l | grep -qx 7 + curl -sSfL "https://raw.githubusercontent.com/stepfunc/rodbus/$CONFIG_COMMIT/allowed.json" -o reviewed-allowed.json + cargo metadata --format-version 1 --all-features --locked > metadata.json + COMMON="--root-package rodbus-ffi -m metadata.json -c reviewed-allowed.json" + mkdir out + bom-tools licenses -e evidence/ffi $COMMON > out/third-party-licenses.txt + bom-tools sbom -e evidence/ffi $COMMON --lockfile Cargo.lock > out/rodbus-ffi.cdx.json + - name: Upload the SBOM + uses: actions/upload-artifact@v6 + with: + name: retro-sbom-1.5.0 + path: out