Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Extend SBOM "formulation" to allow correct recipe for re-making... #3747

Open
andrew-m-leonard opened this issue Apr 4, 2024 · 0 comments
Open
Labels
compatibility Issues that relate to how our code works with other third party code bases enhancement Issues that enhance the code or documentation of the repo in any way reproducible-build Sbom issue relate to work of sbom

Comments

@andrew-m-leonard
Copy link
Contributor

The intention of the CycloneDX "formulation" is to provide a "recipe" for "re-making" the exact same build.
As it currently stands the SBOM formulation section contains strace analysis listing of packages & tooling dependencies used in the original build. We need to add a new section for a "recipe" that provides the exact "configure & make" commands along with how to create a "compatible" environment to re-build an identical build.

@andrew-m-leonard andrew-m-leonard added enhancement Issues that enhance the code or documentation of the repo in any way reproducible-build labels Apr 4, 2024
@github-actions github-actions bot added the compatibility Issues that relate to how our code works with other third party code bases label Apr 4, 2024
@andrew-m-leonard andrew-m-leonard added Sbom issue relate to work of sbom and removed compatibility Issues that relate to how our code works with other third party code bases labels Apr 4, 2024
@github-actions github-actions bot added the compatibility Issues that relate to how our code works with other third party code bases label Apr 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
compatibility Issues that relate to how our code works with other third party code bases enhancement Issues that enhance the code or documentation of the repo in any way reproducible-build Sbom issue relate to work of sbom
Projects
Status: Todo
Development

No branches or pull requests

1 participant