Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
96 changes: 96 additions & 0 deletions .github/workflows/retro-sbom.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
# One-off: a CycloneDX SBOM for the already-published 1.5.0 release.
#
# The 1.5.0 release run's build logs are no longer available, so this reproduces the release
# builds: rodbus 1.5.0 with the release's exact arguments, on the same hosts, recording the
# build log and the two `cargo tree` outputs of each build. The crate set is fixed by the tag's
# Cargo.lock, the features and the targets, so it matches the shipped binaries.
name: Retroactive SBOM (1.5.0)
on:
pull_request:
permissions:
contents: read
env:
RODBUS_REF: "1.5.0"
# rodbus with the allowed.json migrated for bom-tools 0.3.0 (stepfunc/rodbus#201)
CONFIG_COMMIT: e213fea869c48ce7c3972230e4c79f42dd449aa2
jobs:
evidence:
env:
# as in the release build: MUSL cdylibs link MUSL libc dynamically
CARGO_TARGET_X86_64_UNKNOWN_LINUX_MUSL_RUSTFLAGS: "-C target-feature=-crt-static"
CARGO_TARGET_AARCH64_UNKNOWN_LINUX_MUSL_RUSTFLAGS: "-C target-feature=-crt-static"
CARGO_TARGET_ARM_UNKNOWN_LINUX_MUSLEABIHF_RUSTFLAGS: "-C target-feature=-crt-static"
strategy:
fail-fast: false
matrix:
include:
- { runner: windows-latest, build: cargo, target: x86_64-pc-windows-msvc }
- { runner: ubuntu-latest, build: cross, target: arm-unknown-linux-gnueabihf }
- { runner: ubuntu-latest, build: cross, target: aarch64-unknown-linux-gnu }
- { runner: ubuntu-latest, build: cross, target: x86_64-unknown-linux-gnu }
- { runner: ubuntu-latest, build: cross, target: aarch64-unknown-linux-musl }
- { runner: ubuntu-latest, build: cross, target: x86_64-unknown-linux-musl }
- { runner: ubuntu-latest, build: cross, target: arm-unknown-linux-musleabihf }
runs-on: ${{ matrix.runner }}
steps:
- name: Checkout rodbus
uses: actions/checkout@v6
with:
repository: stepfunc/rodbus
ref: ${{ env.RODBUS_REF }}
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- name: Install Rust Cross
if: matrix.build == 'cross'
run: cargo install cross
- name: Build and record the evidence with the release's arguments
shell: bash
run: |
out=evidence/ffi/${{ matrix.target }}
mkdir -p $out
args=(-p rodbus-ffi --target ${{ matrix.target }} --no-default-features --features tls --locked)
format=(--prefix depth --color never --format '{p}|{f}')
${{ matrix.build }} build --release "${args[@]}"
${{ matrix.build }} build --release "${args[@]}" --message-format json > $out/build.json
cargo tree "${args[@]}" -e normal,build "${format[@]}" > $out/tree.txt
cargo tree "${args[@]}" -e normal,no-proc-macro "${format[@]}" > $out/runtime-tree.txt
- name: Upload the evidence
uses: actions/upload-artifact@v6
with:
name: evidence-${{ matrix.target }}
path: evidence
sbom:
needs: [evidence]
runs-on: ubuntu-latest
steps:
- name: Checkout rodbus
uses: actions/checkout@v6
with:
repository: stepfunc/rodbus
ref: ${{ env.RODBUS_REF }}
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
- name: Download the evidence
uses: actions/download-artifact@v7
with:
pattern: evidence-*
path: evidence
merge-multiple: true
- name: Install bom-tools
run: cargo install --locked --git https://github.com/stepfunc/bom-tools.git --tag 0.3.0
- name: Create the SBOM
run: |
ls evidence/ffi/*/build.json | wc -l | grep -qx 7
curl -sSfL "https://raw.githubusercontent.com/stepfunc/rodbus/$CONFIG_COMMIT/allowed.json" -o reviewed-allowed.json
cargo metadata --format-version 1 --all-features --locked > metadata.json
COMMON="--root-package rodbus-ffi -m metadata.json -c reviewed-allowed.json"
mkdir out
bom-tools licenses -e evidence/ffi $COMMON > out/third-party-licenses.txt
bom-tools sbom -e evidence/ffi $COMMON --lockfile Cargo.lock > out/rodbus-ffi.cdx.json
- name: Upload the SBOM
uses: actions/upload-artifact@v6
with:
name: retro-sbom-1.5.0
path: out
Loading