From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Mon, 01 Dec 2025 09:58:49 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-qv1-f64.google.com (mail-qv1-f64.google.com [209.85.219.64]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 5B18wljY012668 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 1 Dec 2025 09:58:48 +0100 Received: by mail-qv1-f64.google.com with SMTP id 6a1803df08f44-8823c1345c0sf40246976d6.2 for ; Mon, 01 Dec 2025 00:58:48 -0800 (PST) ARC-Seal: i=3; a=rsa-sha256; t=1764579522; cv=pass; d=google.com; s=arc-20240605; b=b174NO4HLZaNbU+WncMWcLaM402CfhKVk739hSqecMRTwsMws3xaIts54H0uFyFrrp 13SNYkzWZkiZS2MqX9d6rm2A5oNZf32WOTiqQwqm8mLXjIJor73nyfc126tNSFMPkmQZ v4DCj1McCGqH80tfeD+O8O+rPbX6RBD2pIG63NjUj3FIzmTOLX3Ol0pV1NQErpp6+OfG t9ljEchxMTzVNvTKiFv/OQa2ElAYLb3EQfwoq7e30jSAqeQFnEr74RLy0ElsG9Z2CYWW gdA/TqRGnMdeCIav8R4EldH+yzLsj+FDOgS0oqaMFf8ilK4mkWAQiRXZvMXgvelWCvX8 XENA== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:dkim-signature; bh=3JFP/v1Wp/K0OWjuCfJudWHaTjbjxjy1+KTL0JpkcBY=; fh=6GZQ2Bm6ojc+Syo3mXjVy+wM5IbS6ZBFH1LIdIYBI3E=; b=fk807X0CZZxp5KU3yAs/wPNOvm+WZPjoQSMZ6drOdIiZNy+GHfcnGfng1J4mbYtrXQ h6GFdwV/9iDuRXFrHEhBpC9rJMS9Q6bk8mvjKdDiMgrYG3K3fLj9LxTq1y2SXVSuMr2s iRiIM/FUzhyy5yuxO2keK9HiYSIC++4xFu0HhsjA9+fDLyouNCOiRiLOgBWOCp8YFP/S Cpn3tgPQECrAVcEOMiKGqpOCTzvwtRFbKp+I+6baii9bauyvcXdnzh283ZLedeCenPJW iW1ju6jAMFj9LN51pflHLzxuEqtH62epDYuJslj6DqjHfnQdy7rn6cgTwJA6lzF/Gkvk 1wWg==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b="KGbwu9/N"; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1764579522; x=1765184322; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from:from:to :cc:subject:date:message-id:reply-to; bh=3JFP/v1Wp/K0OWjuCfJudWHaTjbjxjy1+KTL0JpkcBY=; b=Q98fnsvljMHsg01DskIyALW9Y5DlmiNq6SmKmRDe4OWyTKTEKUEeykwrJ5UP/idK7r +yVOtb2Lpi5QfYOPoxugY7JSRtzLm4JWa7jTRefqOJJ4Y25vaRpLHP23afiImmT0CdqT ZqBhYy5iu39ZOU6n8wtQ+Vt8r5qw6iASQREimAhSMWGBgdCy4gHeprrsUYRItNzK/Vgk V5YraxsDkDiCn8DbFNUVCADyKcAHJK11jA5XODoRKbEoMr3DpXqj1uxnKO1I6KcpTbUM rDiVh1CMyaYt4pO99ZqVY7Q96gis2igQVaVs33WIZ9WHAM+lGnBCOzK9woIqJuTDY12h JWNg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764579522; x=1765184322; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=3JFP/v1Wp/K0OWjuCfJudWHaTjbjxjy1+KTL0JpkcBY=; b=Ep0Fj0xKUYKLOTKRqC6sxC6M5lWl9ckx/RRCaAWPOOoticoVDWbgYfqKVeUH6wYgRv +qfRxRNJ6ERelaG0HdGRoLlZYlq436MagVHVIQNIhAx62+QydO+0YdQaqoWWweevZV5L UOROHNbuZZfybJJmQINAZVE/gz527fJkujAAXhxUXmEi9j6hSQpal6+DXcRVZ/W9FBBc AHJhW3KYqQz2KDd13v3Y9qRmvcvKiqp7QS3nDoezivxQgzhdd43Ay4EphyFmyoiq3VjK Yv3anpuKkrMkYaJNhjNv85J3XxUA7ZyJhiNom6XCoNL3O6t9CN4rWBYWS2ZLSEvnpZqL bwyQ== X-Forwarded-Encrypted: i=3; AJvYcCUdVxqDQg1GgpgEzrOLXgGdyeAcGYAnk2R38Pgpn7/CQJOJ23fq+B6KSUv0k/TKMuCH8rx7@ilbers.de X-Gm-Message-State: AOJu0YxZvxpexb5qPk2FhJ9cHKudl+nlhgRNS7qOklMiTSFJ4BUVYxhQ lZKYBlJzPeEuFFshrzhgImWBqNq9H6IFC6Kn0QbyiWYOpGO6wHVeK7vl X-Google-Smtp-Source: AGHT+IFGq70JU13Gl/9AuIkINGteWONBP7dMmXRbqE1AQmSb7BVh0jjmZ7LvqpkZf1vdBhrLNqgjNw== X-Received: by 2002:a05:6214:2b88:b0:87c:b91:788f with SMTP id 6a1803df08f44-8863aeadb89mr346566386d6.16.1764579521888; Mon, 01 Dec 2025 00:58:41 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+aOx/43/5vdzb+7rDZAEpFEpL8O8hXJ2Dcb2NHWrPbuNQ==" Received: by 2002:a0c:f14d:0:20b0:882:4be6:9ace with SMTP id 6a1803df08f44-8864f8bcdb4ls43522756d6.1.-pod-prod-08-us; Mon, 01 Dec 2025 00:58:40 -0800 (PST) X-Received: by 2002:a05:6122:923:b0:55b:305b:4e2a with SMTP id 71dfb90a1353d-55cd77c9601mr7521464e0c.17.1764579520650; Mon, 01 Dec 2025 00:58:40 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1764579520; cv=pass; d=google.com; s=arc-20240605; b=CYqlchhm6UEuWczT8Bdq12rHR9tU7eP0AlIqf01ra4wFa259WwGWngfokNv3IfK6TF Buc1YBjcwazGT7UzhhpFcFH56qUXz7/6MVzraa/ywvs4dDGhikzfCANHLsYuikQ+VkfZ 4E2xRUY+MVH443aXypmp8SHHW6Pxm/6y2PVVI9ostylJplE7c2s5KBrstMvTE411VDt3 9COWY0u434ujkAMAThNLGHI5VZfMmqKUUCUhJRAoYQQwCi4tb0Fp6mce8OFZfnWI8K3n Qn/PvWTQqo5KocFGFhsOI5bJ2PfGTdP+urtbXTlRCVJNI42Dwzh+Q7yX8p6Ty7xmXIS1 xatQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=eELwxLZ8Ccv1VNPXZgZh33ZMUcEizbdWouahKyXZrNg=; fh=YgHcU2amhotomeH1Rv2VyUlgPjm8wpulXwrBvcHF4rI=; b=bSu+CNOoLrcyQ9yb5kR7xND+UE0v4ZjCnuwqq3AmMDPby6wjkMfUJABYVbuZq2z1tw gLcTfji9FqQ0LbAPtTGEhhHhUoT1CiNU2Bsm5kXKbnw7pFbX5zlUeGin8Vpl2NpsE99f QsHw7WTib9MwZPIwv4diFOC5uknldrehG7kv35jy/7qfXuCTyeLD9L9eVOlMwmpLyXgG oIizOTBIac5UtzXrQAHsrr9DdO3pFsRFkmUz48T6pHGYUPKyV0JoDShauaDP4Cfnqs1/ 478eL5P5qnbr9qUlzey+ioCupX9k0VlwB7Fmz4jVvFHBuMwsy+duRDf7kYjvPJ81zUWK J25A==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b="KGbwu9/N"; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from GVXPR05CU001.outbound.protection.outlook.com (mail-swedencentralazlp170130007.outbound.protection.outlook.com. [2a01:111:f403:c202::7]) by gmr-mx.google.com with ESMTPS id a1e0cc1a2514c-93cd69b7192si200792241.0.2025.12.01.00.58.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 01 Dec 2025 00:58:40 -0800 (PST) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) client-ip=2a01:111:f403:c202::7; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=vHKQLeFiohcKVLtWWh2N1MKr6gqSAKE1ZIwL5rUE5VFS6O6eUFj/P56yokIHUGmrz4Rp0RDBzLM/dK6x7IE82s04i7CoL372Pe8f4vKeVhBZBBlo+fl7heMkPmO9OInKl5KSCs6opk6A6JZ04aSt063D6h27Qj4ULTgPimiVR3E7WdFVagPT2Goj1IWX1Qby8TLhnUjNAKsec1NCiNR6OmNOeSxRQp9XDhwfKDBRCX4NZAuaQVKGDYBk2eKcnSp4Xq5k6xKo/n6CEhPAxQ4NimYY/gszLpsRQVi/T/qgkIsn29mnKzp7odCQUb0MaHi1xUum2Tz6Jtz9RCJGdqiJug== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eELwxLZ8Ccv1VNPXZgZh33ZMUcEizbdWouahKyXZrNg=; b=BCKbRLN3dvp4/ozYvVPR+iS8UecKWzLATvqO0dzEyhbabOeKEmRfGwhvDgRdp1p5b9coC4F5tgb/abzBm3YKKFcOWan8S/NQNZvOZyB3hMJ/PeEhzQo+pDE9S9reuNli/2nSsIUpxoytfyC92mRFHi1vKH0kAiZhvQycAFz0ZT1VUu9HhsVPmMrk21dDnkPRVDqmT7/sWPh0exuu4lTIG8jbXeqixzMiU3uEY8mMRbLnSqGXYAAwnRDO6aYZbPeL+uyLrqMdrQMgLadD/k6KNMCEXu9oF7fCArgcyMiIvjud/rbIRmuN3jTXIxaGWTH4ozrZMFk/F4PvZLwJcTv+bQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) by DU4PR10MB8880.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:55d::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9366.17; Mon, 1 Dec 2025 08:58:37 +0000 Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe]) by DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe%4]) with mapi id 15.20.9366.012; Mon, 1 Dec 2025 08:58:37 +0000 From: "'Felix Moessbauer' via isar-users" To: isar-users@googlegroups.com Cc: christoph.steiger@siemens.com, cedric.hombourger@siemens.com, jan.kiszka@siemens.com, quirin.gylstorff@siemens.com, Felix Moessbauer Subject: [PATCH v6 09/10] imager: create SBOM of IMAGER_BOM packages Date: Mon, 1 Dec 2025 09:58:12 +0100 Message-ID: <20251201085813.1616095-10-felix.moessbauer@siemens.com> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20251201085813.1616095-1-felix.moessbauer@siemens.com> References: <20251201085813.1616095-1-felix.moessbauer@siemens.com> Content-Type: text/plain; charset="UTF-8" X-ClientProxiedBy: FR5P281CA0016.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:f1::14) To DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU0PR10MB6828:EE_|DU4PR10MB8880:EE_ X-MS-Office365-Filtering-Correlation-Id: 8f49e17b-39ef-4eb6-cc6a-08de30b7d04b X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?LQmewXKNramFKVxC5fhLjtdiWmDl7fW491m82LDA+Qf2h6djarv6opnZSwlQ?= =?us-ascii?Q?Dr76AkcXJ2rfbUmYVGKGi6VJ1RwvCNCkMfXnWj0QGkLzxAAwCajAvfWVD3sU?= =?us-ascii?Q?Gyc475o+p/OOWGKa4MLH9d2Mon9drdKojdApsvMeUf0Nia9vrO6YnuKKXpa/?= =?us-ascii?Q?gAd9NW8Cw+5gHznl0+Vc8FxLYSIFq2Lf/KCTC6r7BvXKejBn5fokx2TnD7wd?= =?us-ascii?Q?YfWzCAm/ABU/C7h81TDIHrcALL4EFBZKVAusOWjlBdtmJpcSYkksn1pn16MA?= =?us-ascii?Q?6GbqU5hhZX7COiP1l+RKuVBbfDHXDpgfWlTX6D+wM9ROuCGrwMApGhySZMX9?= =?us-ascii?Q?smmMEbpNqFo8aZSqRp1HAUumgjvFeAhqc6zjmz2fNun9uGjpVIus3fZNbpwb?= =?us-ascii?Q?qDqUBgT2wnGu3N2ENQ9R4KCkqtH3/baiAqsKjEt1Hrpoa3j7rDj1xtLfsnLZ?= =?us-ascii?Q?/8coOYSHt7Yfy0J4Xgm2NJq5X9eM+VuL8KHysYo1qHMbevmacF/O8SE9O3B8?= =?us-ascii?Q?Dcv9c3S1zHGxpYUV/lnbMe9olEEceXWgp11KicTWZkjA/uXwnKtiGabRgy0Y?= =?us-ascii?Q?yrk/pvBeLwHb/Jh68gpbD/ZteOUeYN7Elb0PC2RAkhBDOr6+7hOxsiEglcnb?= =?us-ascii?Q?4DX5e3CTO8yvXQMvjeJl95RlgUSSbG/gGnPtYwPMDdWavM5AK+aC6RYYBODO?= =?us-ascii?Q?zrs5D58lcfKkb/UMZpNvln5h9M3CUC9RHKAkS37u+N3nyxEoGu1d+kOqzu4I?= =?us-ascii?Q?t8YkiTqhzFYUJNPy9LrDocBG7HBak5WXOmbNw9cFGyfzoolm9sQe6KiPup0w?= =?us-ascii?Q?3VyizNDKSxEIlCPrZlg7PAYIVzCTV19VHM8PpZEnO3Cz24VZu9ALITr0Yx8W?= =?us-ascii?Q?oZyyt0RnPeYL9ZVQ0AfSim9I4tfi5qpXNzJW3WgTZUnSXQ1OSpwW4dfY6rc5?= =?us-ascii?Q?/H80SUGbv1owPHCRDgNmON0D9epXwYOItDKXDlYR62simblukGftGeruOPXm?= =?us-ascii?Q?eCcCZz/M/xAHlA0iVyjIshi04T1eXKBpGNXbOTbyP2A0xyl9cQNAw15EbqWq?= =?us-ascii?Q?vKEkZJ8C3nyv76gQ4XltaSxoBQn2y4CFR8C9G/jC/0FZpfRMAPyqi3oARu9G?= =?us-ascii?Q?T9Q8N3DTBkA/RNINUT0P9U0UvRZmGHaiqlISjORwPv5nQG395ilta20ler+8?= =?us-ascii?Q?4fOZbhFht5gh+zq329Zvj9z4WorUiKCS7MpqR3mJ2Tlo50y661BAQBDW/OSa?= =?us-ascii?Q?VWyvN0Ew0jatkZCrd84ywCui/ILhfsYztKZM9pucQhJqZfTLLZAFwn5XdDcp?= =?us-ascii?Q?syPSPt4fuZbvzQeGxv6qC5g2MHdTxEqy0L3sPBoBv0oDZt7Uc26GSR6LZbRH?= =?us-ascii?Q?a1qaiKPnLcawEBGySyoTvqGXKbfbQJ1WdUAJIGw0S2VT4I9ZRPYp9MghP4QD?= =?us-ascii?Q?PB1kn//7Ehn0txtLRiAQet897k7aHjqo?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?7r1goKEHO1Sax8iL7GsZFTr+axv4SqVxg7NVSQBB1UgsqZ6lAFKOWLlN+aa3?= =?us-ascii?Q?87zRyuJ5nfuWsFRMNYjYFj9Xjh3eBS16OItDdnTu/iFjznHa9h/DjcaXPC7F?= =?us-ascii?Q?1hj1I4qaTbbpr/QqbK6ldk+TclJHl1kSJegGfADGQeG3XxwEshkVeqJhwt2E?= =?us-ascii?Q?P+4/yk2atpMVXjquD8Eqh5AUthwmpC45dw+ZDNWYkoAnwBPlreyOL2R4Qmje?= =?us-ascii?Q?W2GvMKKWwXNceZRZ9iyS9Y5bawYnEve3ReBrwf2a4NPFHpk9JvmLF532faU8?= =?us-ascii?Q?sfVzI1ncnm/q28YsOj82rLPQHRKq38K04Bl2+nfugcP7gmxu6uHJcrRzNtdZ?= =?us-ascii?Q?TnQd3bXS3GGnLwfaO5JoEu/ZOPQuv9owxVk8rfAjXzaJ3Y4B7PuWucA0LNC3?= =?us-ascii?Q?XIfMTZzoGNQlZrhJEopgCqN/jRAgpd29bG5MYiR4dnrR+Nc/UNe0u++xpEQO?= =?us-ascii?Q?k85eJ32HskXWFCO0CeO0SYeNQtrNBhz8SJREczA7RJPzBOu0mtEz46ZiBO6V?= =?us-ascii?Q?wy6EZxAfynt4h3ZQQPoQpAWv5p183JU8kmQijWiVK/D23egPDzXaJmtoUX/a?= =?us-ascii?Q?bFysU/nyte/Dj9PGol0+sL1oiTM39MRvQU9HYP2rtQdR3eIz6Z6kJQS4VoYS?= =?us-ascii?Q?g8DvIqDmge9w0cDnXOVhn/snXqE1p0+sX1Z+Mukk6B4ARQ1fxdk5Rb9wvxyR?= =?us-ascii?Q?rlYcWs7Ss75TIrVX/OKKJHNflELqG/fOK7HHlVzMHejeo3HzvhMyRiNq//TS?= =?us-ascii?Q?u8yYtECyy5TdJUCv/PnOBZu8nTGkPkXqpxtGBuAzjQw40ogsi8tLFH71EFU7?= =?us-ascii?Q?U9iumnUjcxdsr9p4rSL8ablddtoyb6Ji18pVDCAc+iSUKQoZ77NOaDESmnu/?= =?us-ascii?Q?44sAbITyNY0j/3cKCcp3VX8CtYLhDimMR74IEBRr1P8UOSueRhBjqgI4683q?= =?us-ascii?Q?Wbmqb8aOZk89l8WJAlIuPmGsya9Z2xCQAzYqTh+2+pU7tZGEThC0u6xgYE+X?= =?us-ascii?Q?peShyVsCo2B9LVMOyHiDP1dIzlXkMLXWj79++Fsq7P6HUqS/dRL8uKS1oFiz?= =?us-ascii?Q?2bm2ytOcTwcyYgm6I1VBW4qzrrp9zjk5SnBQwptq8h6LIyPXWKVhptm74wN/?= =?us-ascii?Q?Y6v9N1i3EKzICSGUjXiYFv9ChkehG2AOHdK1h9mA9GfQ8SaXvPRpUZSLqAJP?= =?us-ascii?Q?Bq7bi50ZA6rl7x1eYmGGPKGXDBsTALJVMd6O13nYsGi8FUfDkSXhfjUocpPr?= =?us-ascii?Q?5KFihzTwRiIk9ieA5u7irmcAhyA2Jsh25xsOoHG9VkO5GbtX2pllwwTog83w?= =?us-ascii?Q?PM8nPrUCn1F25JzSkb4byUksxWTC6u5RPgzpHF09jfeuVK+sQigaMv/1k3Rj?= =?us-ascii?Q?oGQzs8sCZlSjwE2fVT8igcj7MJ5JsNlmFAhmlDqG153fP0q0C6aDuOzVlnCm?= =?us-ascii?Q?2E2L1YqGJPZk6z6Vwi07v9d2LuR3cxzjKNuYqZVZ9vicf+xuxgIusUQKnzkz?= =?us-ascii?Q?ztivhM1UnTNe6u+6USNs1lI0+shPfD3hJLq5rSkBQYyQOLCZmyaMaDrZO/T6?= =?us-ascii?Q?c2tXuqxWD0jNwehkSgBd94HVsjX+doPgI3RgRbQ45h7FzMf326aszs5ZGY4K?= =?us-ascii?Q?Yg=3D=3D?= X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: 8f49e17b-39ef-4eb6-cc6a-08de30b7d04b X-MS-Exchange-CrossTenant-AuthSource: DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 01 Dec 2025 08:58:36.6639 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: GvB7XATBIXzf1jTlv/mHNuL8Q/Cd3l5MG++fr3nx8r7fsTs+1ki1zfnpgV6uWMOjBWqwGFe0/QtdxzqFawbw6woomDmvdknfAP6B5cAvwgg= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU4PR10MB8880 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b="KGbwu9/N"; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Felix Moessbauer Reply-To: Felix Moessbauer Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: 5wBJp2SyN6LA This uses the same interface as the .manifest file, but adds the packagse to an SBOM. Signed-off-by: Felix Moessbauer --- meta/classes/image-tools-extension.bbclass | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/meta/classes/image-tools-extension.bbclass b/meta/classes/image-tools-extension.bbclass index 2027effb..95f003d0 100644 --- a/meta/classes/image-tools-extension.bbclass +++ b/meta/classes/image-tools-extension.bbclass @@ -73,6 +73,8 @@ EOAPT schroot -r -c ${session_id} -d / -- \ dpkg-query -W -f='${source:Package}|${source:Version}|${Package}:${Architecture}|${Version}\n' ${local_bom} > \ ${WORKDIR}/imager.manifest + + ${@bb.utils.contains('ROOTFS_FEATURES', 'generate-sbom', 'generate_imager_sbom', '', d)} fi schroot -e -c ${session_id} @@ -80,3 +82,23 @@ EOAPT remove_mounts schroot_delete_configs } + +generate_imager_sbom() { + TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH}) + sbom_document_uuid="${@d.getVar('SBOM_DOCUMENT_UUID') or generate_document_uuid(d, False)}" + bwrap \ + --unshare-user \ + --unshare-pid \ + --bind ${SBOM_CHROOT} / \ + --bind $schroot_dir /mnt/rootfs \ + --bind ${WORKDIR} /mnt/deploy-dir \ + -- debsbom -vv generate ${SBOM_DEBSBOM_TYPE_ARGS} \ + --from-pkglist -r /mnt/rootfs -o /mnt/deploy-dir/imager \ + --distro-name '${SBOM_DISTRO_NAME}-Imager' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \ + --distro-version '${SBOM_DISTRO_VERSION}' --distro-arch '${DISTRO_ARCH}' \ + --base-distro-vendor '${SBOM_BASE_DISTRO_VENDOR}' \ + --cdx-serialnumber $sbom_document_uuid \ + --spdx-namespace '${SBOM_SPDX_NAMESPACE_PREFIX}'-$sbom_document_uuid \ + --timestamp $TIMESTAMP \ + < ${WORKDIR}/imager.manifest +} -- 2.51.0 -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/20251201085813.1616095-10-felix.moessbauer%40siemens.com.