From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Wed, 21 Jan 2026 16:08:01 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-pj1-f64.google.com (mail-pj1-f64.google.com [209.85.216.64]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 60LF7xc0004148 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Wed, 21 Jan 2026 16:08:00 +0100 Received: by mail-pj1-f64.google.com with SMTP id 98e67ed59e1d1-34c93f0849dsf1040237a91.1 for ; Wed, 21 Jan 2026 07:08:00 -0800 (PST) ARC-Seal: i=3; a=rsa-sha256; t=1769008074; cv=pass; d=google.com; s=arc-20240605; b=JHpU3DZg8d2CtLYUrTEB86UTyEPsN9Vm7vEo/VWMCCIuzCGZ7NfduiZfo61nBek2HO gYb6/F83aZwMSwUcCLNJc31iDeiDtgZoWoAiqLTdWxUXftVDQ59rQka1imJDIHOqIXF6 GACVKD/yyEHVYYyvClgno42VHqw3WkikJ1QDhGn1tIDlMfVq7kfnAOii7BHWsa3wdFoH 21kQkv1uxHHzEP8sb6BiBoG6il5Zq5YN18ve3RKCHQ1WL7KukFL8zxwFkLmykjDkekVc Q04p/cgtd+lCjvZcoLAAbFyBVzH5IsKlKEFoaeckE3YTkdCIww24qYTcYFKS3hCXKKd/ tm+w== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:dkim-signature; bh=C5PUilFrSt68+5TCVOMTYk0zyV7dC/h84L2a4bxvuxY=; fh=ROf7bzOIecUWB0dnalt+ugzE2aF74vfsRCV1LenQAeI=; b=OtCI6eGvLMwwK1To4JMm8KsDFKN8Ug9cuyM/FgsN5J78Mm6zXCWRmw5Icjx5CGihon mjkYRJ9EVJ54tQXLiY/pCR8Gc7IaxN5LmeX+q9i7wSPEWr2p1TgLo6hcNmgdGyHB0zwe /uwPpO35R+ryeVRp3UPyG7uG2xcfb8PZ3y/BWAW389h1l8M2lSeI9J8lyyf161hB04/I At62qQofGkmOW0yrSw1ngVWDGiENnZ7oK/qhA1y/Xp+i4IAYOWr4XRwvnBWMP4q3HzNy fOuNwpYy90G8xAETABwCS+ujJgYj1Tc+CVKGHngI+0rfNnmZi/QlaSdiK6ZAZbD82F1C LTeQ==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=WuK4R1XW; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1769008074; x=1769612874; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from:from:to :cc:subject:date:message-id:reply-to; bh=C5PUilFrSt68+5TCVOMTYk0zyV7dC/h84L2a4bxvuxY=; b=v5/Rkn/evHLnme43iTSvtbLYR7zT44/pAWSpMdRuqbUYWqX8V2PfV47eITIJr8a/D9 FtCabWEFxnYS6j64xWAifr3hejrR1EBiHzImiKCxiqXo2f18vLYt/keDa14GOic8lP4N I2HVx1qSU9iVGhdEBQboJVmA7j7O/vE2Wap1i2WJckRPAnqY/ao9cxnDFRoFcsQ5rP28 QIlYSJRzMXFhgf9mPfXT3phYBjtb52Gpow2rascVGy2/YUVHJDz8StOqWQBf2cv3vOW4 PwgbAzGvBR4d4Jw2/yMSNXnBnB3Yh6tQ7cZ5s0EVsveZ0mE0W4aZySS4AVDi/dVI+gWj Cffw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769008074; x=1769612874; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=C5PUilFrSt68+5TCVOMTYk0zyV7dC/h84L2a4bxvuxY=; b=Yed2Fa7Qt4lof7AiP2YzfU3u12LwpeizPrTXISnwbCvFcztbKKKRDH5yKLpWZ8PSez gIF8JFr4jG+WsebSJ/R+hGNZwNqUllTFkxwHo741xMZT4TG/uUpuorYk7OzGCoL/I2iD srnwC+cJ/fvrFrRZunLpyV/uqJ6eN6oEWtkyz/eEoNU2tHOxOgKOfZHCGpOrdugYWoTH UpJ2ONQS1460jIKEBlmPUIf5G7YqjaWU0saOP6+E1N8Ya+5NpuSyCGD/da9z9gKlILXy 4WEZHAFNus2Xw9XUaQ8RTW7O5u5pOa3zUJcAr9IwF9O1ojRejP8i3EUj8jvPk5W202px TC3g== X-Forwarded-Encrypted: i=3; AJvYcCVr6DIc6vdD8UnysMrSWOGALwB/sHUcpEctIFP7mjEn2UQi7p9kK0nf+pIjd0UHxAf1br8b@ilbers.de X-Gm-Message-State: AOJu0YxO3mGx+rVCZuQt3ubR+QQc5JSxRm/0xNEXqJt+4/wWeq+ayxmB 0FPs+3ikBsYkz90qXvSExmM5pL5wlXgfKS7F6LNWMDdGSEEcpMT/sCKZ X-Received: by 2002:a17:90b:33c3:b0:34c:7212:7a67 with SMTP id 98e67ed59e1d1-352678b9b13mr19035502a91.12.1769008073802; Wed, 21 Jan 2026 07:07:53 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="AV1CL+FHpK22FSIrUc0X62J2oVlhUb0quWZwotNQU4xi+0TdCQ==" Received: by 2002:a17:90a:c292:b0:34e:be5f:7cfe with SMTP id 98e67ed59e1d1-352fad4f56cls394574a91.2.-pod-prod-00-us-canary; Wed, 21 Jan 2026 07:07:52 -0800 (PST) X-Received: by 2002:a05:6a21:3a42:b0:38b:e70c:6406 with SMTP id adf61e73a8af0-38dff36821cmr17178777637.22.1769008071892; Wed, 21 Jan 2026 07:07:51 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1769008071; cv=pass; d=google.com; s=arc-20240605; b=Cf1UQC/skdzEW05D+K4Yee7yH8vtL6hft4aU0gBn2mRcqZBva+aq8r0/JNNTptZxAi 3MEBDN4YphKpgON9Gcgv/9n1SOPBit5t1+aTf+yXQdEYURMxH02ET7eA2eLpE6+3QP8+ vVxk43SOluLFEk/6qP7yVsb+upNa6yzuqBz/6k4vHRDILtv1Jfz281n5Uubes53P6WWk Ptbv4adJRXk09dLqPN27hsOgz1FaJTHRPuD6eImsf8fZZOIHk/2cokG1lXIZQHxzG+tv kwie6LvPs0xfyKXF+PLxws/oMRGnyoOV2fIpVTbAFl6h3qbi7kQ/PNXj8JZLP4K4CIX0 foxg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=Wb++9e+nnm+s3psiDz9vEnwh5vH+90FoCyVqABxee9I=; fh=3TZ2kfKzTV0uAG2uKD8NJHxpu4kGHzyonq8tLR1Voro=; b=PMfAl/bVnkC51wP0jLlAafFOz7Dz3ZwRerwWIqHuKH/rOF3H/qrZnQZlP9DQPbCBNT oeQ7V+HmbkOWVX1f2HihEkD0O+jhu3djdADa4OTiT5EPXzWTCxo0vg4zNFBVsRJtZNS8 Qzwx2GNIN+9Aur/mcqtfIUsqZs/+vharf4F+kerq0lbhJ6u593qwRAsakzzDfBXUO+bq GOVrj/4X94YfbuyeiTgK2JOGjwh7yi2ZBdMr+9eDyg3mDkKBV7ND/kZIv2tT+A/ziKqZ 3mHwd36L4ojFYJlIOwrNuMda1UrqLn/SvbKFPTDUqgarNeD/G25clGV/pSgoI7FfLrkt zHXw==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=WuK4R1XW; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from GVXPR05CU001.outbound.protection.outlook.com (mail-swedencentralazlp170130007.outbound.protection.outlook.com. [2a01:111:f403:c202::7]) by gmr-mx.google.com with ESMTPS id d2e1a72fcca58-81fa10bd8a3si651061b3a.3.2026.01.21.07.07.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 21 Jan 2026 07:07:51 -0800 (PST) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) client-ip=2a01:111:f403:c202::7; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ctbx2KP2uehws+YqKIn17YAMdyTdIDMIU+bQAkvoI1tnXDTnIG1qIjBj19gQGJrWtSTHP4ymngxXrV3XJ8zxBqzsWgWAsef2sFlN7qnQEMYEtMj9rWzbnOwX38OkgSIY1YeZhVjGoayDw6e2HwRtTJ4cqYZmDTlOS5WBpVNSrN+3N/gvMkk0QsMUStM9JS2v82MaKBH8xC5vJANRBzsyxunxzWGK4lpY4mC5I1XUpIolWLYOqweUNSSh/W6f2dL+NeYDJnTFrJkE4ycQvZB7exPT5ZvauGVk8Qabs1YcfDSU9qruiP7iVvnzFA4BU97gRX3/d6eu4dR/I6sRva1phQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Wb++9e+nnm+s3psiDz9vEnwh5vH+90FoCyVqABxee9I=; b=Ux6Dpzfn9/zK/s72fN6DvMknk2toA78RESChBGLIeqIv4Zasdri1rGmHuG/QHMCBwFhsUUqBZaTZo/fkHqkNg/fCLD5g9HS3dv6BSpu0NAj2TbDkq8XhCn591m8CrXYRTahJg2KLAlaC2qaAVjIft9/7Z5CnmsOsxUbAbGxDFaf5wu/DQpzOkqCDTAAzV45zncmlScDghaY+h/KEQmb5gkTbdseFiaqwpR8IE4a06GnnQ9aabydpC95xVbvMDSfNaO4IYBCXb8NC0PlkH/5O+4hbsyekHz8Jeqc38ZU9iogMusXAY91qOZ5Qx9tFcExsXY3r9OH+rW4TZkGA6gyhgQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:5f6::12) by VE1PR10MB3806.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:800:148::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9542.9; Wed, 21 Jan 2026 15:07:49 +0000 Received: from AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM ([fe80::349d:731e:a849:b4a5]) by AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM ([fe80::349d:731e:a849:b4a5%6]) with mapi id 15.20.9542.008; Wed, 21 Jan 2026 15:07:49 +0000 From: "'Felix Moessbauer' via isar-users" To: isar-users@googlegroups.com Cc: christoph.steiger@siemens.com, cedric.hombourger@siemens.com, jan.kiszka@siemens.com, quirin.gylstorff@siemens.com, stefan-koch@siemens.com, Felix Moessbauer Subject: [PATCH v7 7/7] wic: create uniform SBOM describing all image components Date: Wed, 21 Jan 2026 16:07:19 +0100 Message-ID: <20260121150719.2719579-8-felix.moessbauer@siemens.com> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260121150719.2719579-1-felix.moessbauer@siemens.com> References: <20260121150719.2719579-1-felix.moessbauer@siemens.com> Content-Type: text/plain; charset="UTF-8" X-ClientProxiedBy: CH2PR17CA0026.namprd17.prod.outlook.com (2603:10b6:610:53::36) To AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:5f6::12) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS2PR10MB6823:EE_|VE1PR10MB3806:EE_ X-MS-Office365-Filtering-Correlation-Id: 66720e0f-7753-4114-c040-08de58fed73c X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?MBlZN6jz0wdcqBmPnyg2loWfxU1beCO1mFUg3bk1tzrV40dM6Cqq7UWI0uw9?= =?us-ascii?Q?5Z0IrnTbgqVAauI4J85By/1/V/gi3s+Wha08GfgDT9ynK2KYrq3duGO/PgR0?= =?us-ascii?Q?ccG8Hhi6nfTpq6ndSggIVNOeN9t0ilkteiAFqhBRhDC8XWC4tiXOes53aCyX?= =?us-ascii?Q?qIVg0Au8d/w6A0HyYXM3NGxyfj0J7Jd2w6838A2ohAbgQs1bNZBt53rwOhTG?= =?us-ascii?Q?NAHmvGxKB5+IwvpCooCuOQ36TUn9XA7P7D/4dATk+jdPkosRKXk1T8jn9xdM?= =?us-ascii?Q?5LZuJfcrqxDfqquM57YvTkduvnvAD1ZoFnawhdRcJT7s9Tx5TNpP+N8LsYwS?= =?us-ascii?Q?2eTTMmIWKUVZ64pZGlKfOeTxdHNp+n+46U0CniLIFiLPEIc/lENAXzbndICw?= =?us-ascii?Q?fRayzE9Bp7hEoF4WT5lLZLRoUntFSlGmI3974RMFHMaZT4GyqSdWeyRFZnv2?= =?us-ascii?Q?GeinNuIUmnl7bqzoV/h+V5lPW8VmUogZ9uAGnKCf0GFA6XTIORuVP0eU1eu1?= =?us-ascii?Q?3mdwwUZ7m3xM7/PfmrEkMZTRdDLw5sp0X8Jn33VPiaVyY10aWhzrxYMpJuaS?= =?us-ascii?Q?uSNulc4Ew5j4SeHABWbki56iyWa0nN4hC9hcF1xKO6q8D/4SkZBUI/ZzKgqF?= =?us-ascii?Q?WPnxx5jrUt3Vh2hPDjZ0KYWXHhZNhpw0HvRYOKBu5SsA9MXLMv1f1mLL6Jt/?= =?us-ascii?Q?g7M42lp/+23LeEglJjTCfLWeO5xfVLb57VJfK22bJ3I1Oq7lLKU3opGM3ZJS?= =?us-ascii?Q?I3h/Vk0vqAhD5Y5fcYwCx3L9MuZ0vWJXa03Y0C4bAp6rBP1vzKZi2kqA7Gh0?= =?us-ascii?Q?nyl1Cdcp2Aqdix3OkhWNyIebHx0bv/BmpuxDK9O5uZXZGHfuc6V2OE7fBwxn?= =?us-ascii?Q?hpif8A2VfSCiEz8R0prP1CbAFyUISRwxCVNo64Ulswz8Pmar5LytwK5yyLL2?= =?us-ascii?Q?BNjasY/M5knS7m+Lbc5+RO+OLHzy38TSwOD3VyAHy19+DbUqPFln6RcW2413?= =?us-ascii?Q?wxGeviZz3N5M1+BmUs6/mFVxFJP8ngujDbK52VixZ/5gOvmX0olqVbkqwCxn?= =?us-ascii?Q?tb5x4xffocHoCpXfz4Uu9fqq1f/PLCl4eFbh9hGNxAwl6qP+iOBoxqtiaK0e?= =?us-ascii?Q?/jUQ499Af5PjVf5h3fPfCrUFoWmM5N+KHCFwwt9KI2R43atrak9Aqq/ec+fx?= =?us-ascii?Q?2Em9mQG8Ezi0PnGQ3HlxLg0lfdjKWGlWzHmi2kGJiyw7AjW8TrwtjPb2Wq69?= =?us-ascii?Q?AXBm7JBGmeBq5AcqFvM8QgT2vld3oP1cQUd2AkclLWxC1x6ohdkbftoYT/wm?= =?us-ascii?Q?YqlhfyVVfyVZyjGIvFdIORQENprexSqz7CLP0yIjn8wzWUz+Dv6P5n3rDCeq?= =?us-ascii?Q?AkAAx1s0/HpqedCtk49Zif3NuCYjhwNp0I4r0VUWiTtTrTBKd9DEqq9wtx32?= =?us-ascii?Q?xGQek8wI1IDUOiUWXG/eyP0RtNIkUODh2isSGlBVaHouuXBHFf4pxK1nKBpQ?= =?us-ascii?Q?M9GGDRWBEOqfVlNfu1iHN6d4f/CDGxJsZ2CtylCQbrMkW0KwDujPYY10Ekf+?= =?us-ascii?Q?/+2azrgA6gldbkGmric=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?tNC5eHVoz9RiumXabjaLCZa6Qj0S22bZwqc4Jt6CkNTyzVvbKBG4CVVUKN1Y?= =?us-ascii?Q?hiHI5VkjC09advIab5IoMYDT0LYdUA7OKcIeIuDjlTjkFApMWyMWCihK6i4o?= =?us-ascii?Q?wcXljREnkGby63cmErXNJQIRnom1fLDho4ScsDfx6TPP1mURPcUsz8w48ega?= =?us-ascii?Q?TAbBYVb20m0qEQAaDcJF76MjEV2SI7SPAI3lBbYvSvABgHtYxsunOZWIBLW3?= =?us-ascii?Q?qXr5yRXTPnUTzNGBumzhY87iwNiU41IohgxkHsysJFfgwTZQhnPOPjuarwb5?= =?us-ascii?Q?x9xCF8I4pSFdqhLJdvRzEV6P3zOUL535qC4/1A2q5vHTtrfjoz8lUWDz8ofp?= =?us-ascii?Q?D190OC3iNtwbN5kH9jBWVCVSv4UinAENk7H1F5p+ZIYx8IGMc1mzFkuB+6vn?= =?us-ascii?Q?mpCxJHqfTds/T516TMXVqtbVQEfgpbaSFP0w5n6H8pjQdsv6IUK/nxJiB9pr?= =?us-ascii?Q?+SoOgXTXBkxHHcp80crCCW/BXQIDASRdeEnxd5e8drAll35f51zlbnhOR/vm?= =?us-ascii?Q?7hOcDMfxvs+c7S6Qa8o/lZdWxGCGkYJaW/h7hGfAZfR29ioMgijkxWk5TKdR?= =?us-ascii?Q?0oXHqfFjkEWLOndc1ES9UUN2GPDR49FsTnbSGXJSZ8J+Pa13lf/deSm9EYJr?= =?us-ascii?Q?HdoStEOPdqBOzaez1tGkyF1CN8UpU9JBEXb+iNIVyFtuu/SgQ7Uj4O7I0LPH?= =?us-ascii?Q?9UbmIOT2tv9cIOCAUvWzjBFggr4p66Fg/zzT83dfRHvBm3F7ev7Kbp/EwAbx?= =?us-ascii?Q?H281l8o03z+FNNsC8xLunjn7UNZMSgCzkAV4uGoDF2YUEaQK+QKGEJs9jeo6?= =?us-ascii?Q?N9HUrFizrenaVkQi5ET0E2vxsaFkJsKCg/LCI4+07vBK4SOba/wxt2WjRGhA?= =?us-ascii?Q?/VItyod+gclPlfdV1zZIFaaSBckwF9Z+pmw2iQYdPA70fs7EWY7iYPw1ZYhZ?= =?us-ascii?Q?mEp8zrSToinaqAM4oy3Hxm6+4nz7jWpK1MD71oI7SIZ7214Fsi872pWPq40W?= =?us-ascii?Q?9oYnB8exn/lts3W3iXhwS7v9rLzFYEdJcAv7RT24vPYCS0aOW05v25VNuBO2?= =?us-ascii?Q?z3YCNlpam8HDQR6CiKZyUbA21HYdUu9X42aMz8iU6cdnCcDD5Yv4v+FSCDlq?= =?us-ascii?Q?YhD9DBJEN8OCUVP5LLeHi5UPsmNtgdT05LLdkGedmeaeYuE6GFzoqGTKlFjK?= =?us-ascii?Q?GenspMiXpkzPPoXxyLjPtHTY2aFnLtJGHfi4nb3v4VcWxNA3qJ7iaZU4Kv74?= =?us-ascii?Q?IIg7Md4hgFJtPL38zlXY++4GQlDXZ8BFCnQNm1/CwORI9vG+JH3SAO1j/fW0?= =?us-ascii?Q?99Bbgohz3hqCAh/Iu1hPUudnQlQaX+rHgOwPbr0ru18AYq+azqHx2TLfVSgG?= =?us-ascii?Q?ywOt1gzXNbkPE/kpjovqwUS8bO59YPCTv/H8SvQocojBDNLtpL2QF8aLbnPS?= =?us-ascii?Q?wMo9RnB2gKAZv45gD577mNzktmD8g5TQUXgTQuGuG416YeRrNQBQNs2LdIJf?= =?us-ascii?Q?SXE4/1O0cxIg3gKnhG7iGhBTVqXWFoZLFvcuN6EBfIu/Y0i+sVkebVRObW85?= =?us-ascii?Q?6IbCRy9ctoHbWZ/am/ZAZCCzCS+0oJ97/GkM8yDRSvetcwGK2K+qM9lyDZWx?= =?us-ascii?Q?QXVkl+JwL1SEk/xxxkHocAC4PDzsH53+F4Z/81q6cjRz/MzFXEmnh2/qxa8T?= =?us-ascii?Q?ZCd48imJu4eBDeVh3/COpbTs5L4hd3lCGk5KYkD5Xfnrvc3cXpWlA1TyGWse?= =?us-ascii?Q?Tm4XKPUKLYYUaKL0IeVFht8pbPskz+8=3D?= X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: 66720e0f-7753-4114-c040-08de58fed73c X-MS-Exchange-CrossTenant-AuthSource: AS2PR10MB6823.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Jan 2026 15:07:49.1975 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: URxXb8AjNwRUAj7VZPwycQhhQNPOfl0+R6komHu0dZJxGPazpEASO4WrzJmT536IKlbMtpbH9raSD0wtUhsAo/cV/ow/Vhc1/Ikvx4yqzC4= X-MS-Exchange-Transport-CrossTenantHeadersStamped: VE1PR10MB3806 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=WuK4R1XW; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c202::7 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Felix Moessbauer Reply-To: Felix Moessbauer Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: 2hIzPAhE+CaQ A wic image consists of potentially many different components. All these should be covered by a single SBOM. After creating the wic image, we collect the individual sbom files (rootfs, initrd, imaging) and semantically merge it with the debsbom tool. The merge SBOM is then deployed as .wic.(spdx|cdx).json next to the wic image. Signed-off-by: Felix Moessbauer --- meta/classes-recipe/imagetypes_wic.bbclass | 25 ++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/meta/classes-recipe/imagetypes_wic.bbclass b/meta/classes-recipe/imagetypes_wic.bbclass index c75d481d..fe31e4e6 100644 --- a/meta/classes-recipe/imagetypes_wic.bbclass +++ b/meta/classes-recipe/imagetypes_wic.bbclass @@ -201,4 +201,29 @@ EOIMAGER ${DEPLOY_DIR_IMAGE}/${INITRD_DEPLOY_FILE}.manifest \ ${WORKDIR}/imager.manifest 2>/dev/null \ | sort | uniq > "${DEPLOY_DIR_IMAGE}/${IMAGE_FULLNAME}.wic.manifest" + + for bomtype in ${SBOM_TYPES}; do + merge_wic_sbom $bomtype + done +} + +merge_wic_sbom() { + BOMTYPE="$1" + TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH}) + sbom_document_uuid="${@d.getVar('SBOM_DOCUMENT_UUID') or generate_document_uuid(d, False)}" + + cat ${IMAGE_FULLNAME}.${bomtype}.json \ + ${INITRD_DEPLOY_FILE}.${bomtype}.json \ + ${WORKDIR}/imager.${bomtype}.json 2>/dev/null | \ + bwrap \ + --unshare-user \ + --unshare-pid \ + --bind ${SBOM_CHROOT} / \ + -- debsbom -v merge -t $BOMTYPE \ + --distro-name '${SBOM_DISTRO_NAME}-Image' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \ + --distro-version '${SBOM_DISTRO_VERSION}' --base-distro-vendor '${SBOM_BASE_DISTRO_VENDOR}' \ + --cdx-serialnumber $sbom_document_uuid \ + --spdx-namespace '${SBOM_SPDX_NAMESPACE_PREFIX}'-$sbom_document_uuid \ + --timestamp $TIMESTAMP - -o - \ + > ${DEPLOY_DIR_IMAGE}/${IMAGE_FULLNAME}.wic.$bomtype.json } -- 2.51.0 -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260121150719.2719579-8-felix.moessbauer%40siemens.com.