Skip to content

Generate the license report and a CycloneDX SBOM with bom-tools 0.3.0 - #8

Merged
jadamcrain merged 2 commits into
mainfrom
bom-tools-0.3.0
Oct 9, 2026
Merged

jadamcrain merged 2 commits into
mainfrom
bom-tools-0.3.0

Conversation

@jadamcrain

@jadamcrain jadamcrain commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Closes #7.

Same migration as stepfunc/rodbus#201 upstream, so CI is in place before the next release.

Changes

  • RODBUS_REF: one variable for the upstream ref, instead of the same ref: in three checkouts. Between releases it points at upstream main (now ec1a587, the first commit with the evidence script and the migrated allowed.json), so this repo's CI keeps checking that upstream builds without serial.
  • Build steps (Windows and cross): upstream's .github/scripts/build-evidence.sh with this repo's arguments (--no-default-features --features tls); it builds and records build.json, tree.txt and runtime-tree.txt. The evidence is uploaded as evidence-<target>.
  • Packaging: bom-tools --tag 0.3.0 (replaces allow-list 0.2.1) produces third-party-licenses.txt and sboms/rodbus-ffi.cdx.json; the SBOM is uploaded, and embedded in the .nupkg next to the license report.
  • Release: attaches rodbus-ffi.cdx.json as well, and first checks that RODBUS_REF equals the tag being released, so a release can't package an unreleased upstream commit.

Releasing

Set RODBUS_REF to the upstream release tag (same version as this repo's tag), then tag this repo.

Same steps as the retroactive SBOM in #6. An all-targets approval check of upstream main's allowed.json for these tls-only builds finds no problems.

Same migration as stepfunc/rodbus#201: each build records its evidence with
upstream's build-evidence.sh, packaging runs bom-tools 0.3.0 for the
license report and the SBOM, the SBOM is embedded in the .nupkg and
attached to the release. The upstream ref is now a single RODBUS_REF
variable.
@jadamcrain
jadamcrain marked this pull request as draft October 9, 2026 22:57
@jadamcrain
jadamcrain marked this pull request as ready for review October 9, 2026 23:02
@jadamcrain
jadamcrain merged commit 47f89d9 into main Oct 9, 2026
9 checks passed
@jadamcrain
jadamcrain deleted the bom-tools-0.3.0 branch October 9, 2026 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Generate the license report and a CycloneDX SBOM with bom-tools 0.3.0 at the next release

1 participant