From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Mon, 01 Dec 2025 10:15:27 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-pl1-f185.google.com (mail-pl1-f185.google.com [209.85.214.185]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 5B19FQ3G013449 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 1 Dec 2025 10:15:27 +0100 Received: by mail-pl1-f185.google.com with SMTP id d9443c01a7336-2956a694b47sf51256925ad.1 for ; Mon, 01 Dec 2025 01:15:27 -0800 (PST) ARC-Seal: i=3; a=rsa-sha256; t=1764580520; cv=pass; d=google.com; s=arc-20240605; b=XtZQx/74K4os6zOsWLqJo2VF4rAa6Tly1k9gH6GwC9zhaOtsq4IhoibxotFk9aR1Aj 0mtMjYrYYD6YL0LHrWdw74lQaC3fZuhlv2B6og+TzPp2DODNtW67tKVOKPrmhhwftcU7 7fQB15Y8RbGCqgtXlUKc7Kby493JbUnSwJLBwdaTq6zbimZ6NELctQLmbiBLbMjKLZuF NHLkjnNNMs4wbGYDvPTcz/sNJnoMz5bOew9cDPg1SleBLQysF8R5wLhUdUVq2kgwfMwf eNDVNjyt3yY5x146eIpPuanfFCITQWtLifinhs/o9625xB7SSE1zheIze65NTxcv88zB fkSA== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version:in-reply-to :autocrypt:content-language:from:references:cc:to:subject:user-agent :date:message-id:dkim-signature; bh=JQS6AnvY8HNbwE51gFbUTO0w8DU7bGquK0PmmaQT3u4=; fh=DnJ4ssN0o5doIcfdWPYuP/4i74cbAApD2nhWGcPZbVo=; b=XaXOiCTZmIbGi9GGOZzwiPY+BKT02N71k7mlwmGAMJVfBq+wW/GEorb/x8Zt3qWEsP Twlk4H4/n2XirJQ1xJ7QsYPnq1nho0VCgOQNXiLVLiATj4p4i+aMQzPDbqshuJG7O3Dv 31DiRTNOEH04LJol6RI8Nvz+4AR0B0vW9iUQFWwcdls4bJj1R8g1aa12/gD4i9nbTiXJ /mwywrhb+cY0JhaGpWW/Yz81knRkEsjzZLRk5XAVRvcma4v6Kx2JcSNIChak1c5m2XWk lERsP1dQiDeGRBXGOoE73vQtpVWB7F3oB526kWAhWbD6X4p57qn/d8U028+w5KENC+X+ s7sw==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=WRaGyYh0; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1764580520; x=1765185320; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :in-reply-to:autocrypt:content-language:from:references:cc:to :subject:user-agent:date:message-id:from:to:cc:subject:date :message-id:reply-to; bh=JQS6AnvY8HNbwE51gFbUTO0w8DU7bGquK0PmmaQT3u4=; b=pBxo30vRUCt90DBfk0nUmZ9Pa1UrmIWNRzTj2oi2gkgTX0rDCaH1lKRI69ssHqlL/o 8J2IaLgovlSoKu8LvXXWgjOS1vfW/4xgpIJbjTAf7HpWyaGf4TsFRvCD0buejJzZQeki LgQMlRqkgVYpwyJHJEiqNuUs7CSbmlOkLt7BMzB7MvQ+ilXyfId92f91nUBTxjhBzA3A KMCNbSUheHZ6J0B9I1KJGDSfp+9NEv+5k7dgf5AqyrHxso+/oOv7XwoRAhTszbALtQ9v q/aIURgZbay0z/DOQ/QGO2qf5N1C9ltnwqqAMg5EW00qlIDRsNs/fkSivfZ9r7aDQqmh nmdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764580520; x=1765185320; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :in-reply-to:autocrypt:content-language:from:references:cc:to :subject:user-agent:date:message-id:x-beenthere:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=JQS6AnvY8HNbwE51gFbUTO0w8DU7bGquK0PmmaQT3u4=; b=WsiCQ8V5uBOJcukJY0u30ekGhoybZ8zVNj/ilfgUJwaY/DYeEhdx5Bbw9aLA0qo83Y BqulmjTSpSjCYaG7ttFPPXfh9vO8ZOCJAGt7bMHuZFP1V90PNZK+N5exW1qrM2Hcudbs KB+w9KPV/jY71nZpwwZMQZUekLyrzH9TPtKVReyFa0ZXb7WB29ovT7D1PazUms2AgZu1 IPmz+9PXD0fLN3RlOsCq4x3wKXgJKV9PbEXtI1MiyWPrmHWjWjwWAFj9meq7d3qNx4rm akPCj/rvgbNyGVmjfG0ia1S6E0VI/UlNizFwcfVhbCLyF4dAri4hC6j6iv6kC1hW4WSr wznw== X-Forwarded-Encrypted: i=3; AJvYcCUT3KmxW+C5PXjlL7AZkPH/aw/rxAd+BF3pewXd87ghJiwzmwZiR22F3u7i7HWGWiAztYfs@ilbers.de X-Gm-Message-State: AOJu0Yz4sFoRu2ejw91S7B2l1zBWPX0uGQmF9OeTgby6F46PKvYTHEHd s606JQld2BcKMNlclBmlLcSJUrQ7ze28gL/uJw4/ZfnzsSfCoxDOEiNN X-Google-Smtp-Source: AGHT+IHbvwdRlClzCEZH3hFfMtquo7XZwE+i12GYrmkQIHySazdbjeZTKvQpX7IAYAzkgxBj2dmaIw== X-Received: by 2002:a17:903:acf:b0:298:2637:8029 with SMTP id d9443c01a7336-29bab2e52e3mr248211095ad.55.1764580520178; Mon, 01 Dec 2025 01:15:20 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+YOqS/BBqDc1K6chUDcHcIL3wEelpQ5u0ijP18wTxPJIg==" Received: by 2002:a17:903:3d07:b0:295:3ebe:5b4b with SMTP id d9443c01a7336-29bc93e8f32ls38498115ad.2.-pod-prod-09-us; Mon, 01 Dec 2025 01:15:18 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCU117nIBkToQ9x1cJ0xpHMo2HxRn/TbRB+8169pE6QnbcEp7Hh+Tu2TPonORUV0q90THEXv4YRuBfwa@googlegroups.com X-Received: by 2002:a17:902:daca:b0:295:59ef:df96 with SMTP id d9443c01a7336-29baaf8aa2fmr242186845ad.13.1764580518504; Mon, 01 Dec 2025 01:15:18 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1764580518; cv=pass; d=google.com; s=arc-20240605; b=PoKkMUbH16mSXBhAPrB9lct/UStiZtioQdrYAA/PidRwf64/e0myef1qqGknbfukJO D2NcpLZLyCzmkfjvL/qmjIa2KOS875TpDmrSvu5Z45wvvhm7tbzOhNDtnYCvS721bcSc CSiZHiq0OMY8Ch0f69m1mhV8JnY+lDzIg7IQ9yogm9fyUgh6AxPEqxkU63ZHfwFiFZFX hkEEzWmt3PkONUaUNFF1OpbePuZq4HpoiZ5Lslj0d4NIwxZIXuaUwPiYmMfDMv9/etpm 6D6VwWvMnXEDZyp5cSBBu1cRXhCTrlNUfc95f9y32HLuzH5OolZWD80rpVNJXmL2zLH6 qmRg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:in-reply-to:autocrypt :content-language:from:references:cc:to:subject:user-agent:date :message-id:dkim-signature; bh=rq7JiKFMSj2T6MME9PMcKF4/ocpf6v/OSuRYftbwEpI=; fh=fqcZrbk8Ndqbb5I+7X1MMiqqjH8FYHaCxxBCdBARHmA=; b=YSX0ww0Yxl3QLkZBkawgKQk4Lk14HsZ3b8zBaV+jgCStiSrwtx4DsdTCM1CfdkbtY7 ZJ5T4eYtiHb8nRNnOaIuczdyK90c/imLfPI1zObPrRc5Qp9n7Einq+IX9ROhO+G57AEE PvIn5Q5ear8CymQsOqRsdSEEDlFkcaDtYw1gHuaZh6p60gnj+TGE7RyKPYcH6dvbKTBd xzEXIMsrhm0zxQ20HJM51g2kZ4n4/CsaLfC4fy7eTypt4U5/2KYb3Aoq5UEgqdBqwrz8 wP/er0ec84ZMm3SXzYmHSHem3fgn0wK3Rijxz329TQ4Tqw9pYHkH+xe/2KMC+eeFsyUu Nh7w==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=WRaGyYh0; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from DU2PR03CU002.outbound.protection.outlook.com (mail-northeuropeazlp170110003.outbound.protection.outlook.com. [2a01:111:f403:c200::3]) by gmr-mx.google.com with ESMTPS id d9443c01a7336-29bcea8ea1asi3314785ad.6.2025.12.01.01.15.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 01 Dec 2025 01:15:18 -0800 (PST) Received-SPF: pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) client-ip=2a01:111:f403:c200::3; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=NYv21aYPr+CEcUKaaXskocvCBy6A7U9O4E7t7jQ5cjW2+ePpeCMydETv/UoSpJLcmqIonN3iUD3ac+i1MfXDLZATDoHj/vb4KrxDmVy0m0nGCQEymYObKkhrRyEHQIBSgO+GjVkf4q39aBxRb6UpdVJHxVNfrSK+vi0Da+Fn1xutlRsWJDFwnmQ+PXra71aMYp/naCqgeOJnkX1ftDrdqdZX3azeZl4oMUug/Xl1F/xJSMDwB6GJx1Z1UioGSkox2oaH2N9QI3rp+t2svV/VkHIqoqNDVUZ/dZ//q7XTHPAAIHFD7Vl4I6KvGQYFH9X13ohZvi8AR47Iou25QghSKw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=rq7JiKFMSj2T6MME9PMcKF4/ocpf6v/OSuRYftbwEpI=; b=bDFqPMJJqi/XbwQlkWQE7th5VE9aNDoarsxjWtBcC94Vjfvb88rrDUMiK7eUV/u4/+IV7l40TuKmf3Bo7Xp7QbIaGv/daUsas7klEopoVe5ieodbE682qwoJJbb4MjWg+FfUXlUCrXZj2ykKqfUC9oiEy3o2rVUh94tSzB9JW3dpU86X1/pN0GdCnwY8fpFlT6Fm/KToJJRtVbyGy6GWoZ+5KaE9mWafeK1gHFnCGEwbDziP04BpyxNhBXP5EsGtj9X3Sd8D0nPwK9dvnQ5TCUUrUxjvTK6RD/2tTgyttS1Oi3nQhq/GWDSa6+UYUEkHTM7MLzWbxthPzAnK8EqYVg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) by AMDPR10MB9522.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:73b::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9366.17; Mon, 1 Dec 2025 09:15:15 +0000 Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::8fe1:7e71:cf4a:7408]) by AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::8fe1:7e71:cf4a:7408%6]) with mapi id 15.20.9366.012; Mon, 1 Dec 2025 09:15:15 +0000 Message-ID: <20caede7-0708-4ed4-8aac-084bffaa6887@siemens.com> Date: Mon, 1 Dec 2025 10:15:13 +0100 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v6 00/10] Add SBOM generation with debsbom To: Felix Moessbauer , isar-users@googlegroups.com Cc: christoph.steiger@siemens.com, cedric.hombourger@siemens.com, quirin.gylstorff@siemens.com References: <20251201085813.1616095-1-felix.moessbauer@siemens.com> From: "'Jan Kiszka' via isar-users" Content-Language: en-US Autocrypt: addr=jan.kiszka@siemens.com; keydata= xsFNBGZY+hkBEACkdtFD81AUVtTVX+UEiUFs7ZQPQsdFpzVmr6R3D059f+lzr4Mlg6KKAcNZ uNUqthIkgLGWzKugodvkcCK8Wbyw+1vxcl4Lw56WezLsOTfu7oi7Z0vp1XkrLcM0tofTbClW xMA964mgUlBT2m/J/ybZd945D0wU57k/smGzDAxkpJgHBrYE/iJWcu46jkGZaLjK4xcMoBWB I6hW9Njxx3Ek0fpLO3876bszc8KjcHOulKreK+ezyJ01Hvbx85s68XWN6N2ulLGtk7E/sXlb 79hylHy5QuU9mZdsRjjRGJb0H9Buzfuz0XrcwOTMJq7e7fbN0QakjivAXsmXim+s5dlKlZjr L3ILWte4ah7cGgqc06nFb5jOhnGnZwnKJlpuod3pc/BFaFGtVHvyoRgxJ9tmDZnjzMfu8YrA +MVv6muwbHnEAeh/f8e9O+oeouqTBzgcaWTq81IyS56/UD6U5GHet9Pz1MB15nnzVcyZXIoC roIhgCUkcl+5m2Z9G56bkiUcFq0IcACzjcRPWvwA09ZbRHXAK/ao/+vPAIMnU6OTx3ejsbHn oh6VpHD3tucIt+xA4/l3LlkZMt5FZjFdkZUuAVU6kBAwElNBCYcrrLYZBRkSGPGDGYZmXAW/ VkNUVTJkRg6MGIeqZmpeoaV2xaIGHBSTDX8+b0c0hT/Bgzjv8QARAQABzSNKYW4gS2lzemth IDxqYW4ua2lzemthQHNpZW1lbnMuY29tPsLBlAQTAQoAPhYhBABMZH11cs99cr20+2mdhQqf QXvYBQJmWPvXAhsDBQkFo5qABQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEGmdhQqfQXvY zPAP/jGiVJ2VgPcRWt2P8FbByfrJJAPCsos+SZpncRi7tl9yTEpS+t57h7myEKPdB3L+kxzg K3dt1UhYp4FeIHA3jpJYaFvD7kNZJZ1cU55QXrJI3xu/xfB6VhCs+VAUlt7XhOsOmTQqCpH7 pRcZ5juxZCOxXG2fTQTQo0gfF5+PQwQYUp0NdTbVox5PTx5RK3KfPqmAJsBKdwEaIkuY9FbM 9lGg8XBNzD2R/13cCd4hRrZDtyegrtocpBAruVqOZhsMb/h7Wd0TGoJ/zJr3w3WnDM08c+RA 5LHMbiA29MXq1KxlnsYDfWB8ts3HIJ3ROBvagA20mbOm26ddeFjLdGcBTrzbHbzCReEtN++s gZneKsYiueFDTxXjUOJgp8JDdVPM+++axSMo2js8TwVefTfCYt0oWMEqlQqSqgQwIuzpRO6I ik7HAFq8fssy2cY8Imofbj77uKz0BNZC/1nGG1OI9cU2jHrqsn1i95KaS6fPu4EN6XP/Gi/O 0DxND+HEyzVqhUJkvXUhTsOzgzWAvW9BlkKRiVizKM6PLsVm/XmeapGs4ir/U8OzKI+SM3R8 VMW8eovWgXNUQ9F2vS1dHO8eRn2UqDKBZSo+qCRWLRtsqNzmU4N0zuGqZSaDCvkMwF6kIRkD ZkDjjYQtoftPGchLBTUzeUa2gfOr1T4xSQUHhPL8zsFNBGZY+hkBEADb5quW4M0eaWPIjqY6 aC/vHCmpELmS/HMa5zlA0dWlxCPEjkchN8W4PB+NMOXFEJuKLLFs6+s5/KlNok/kGKg4fITf Vcd+BQd/YRks3qFifckU+kxoXpTc2bksTtLuiPkcyFmjBph/BGms35mvOA0OaEO6fQbauiHa QnYrgUQM+YD4uFoQOLnWTPmBjccoPuiJDafzLxwj4r+JH4fA/4zzDa5OFbfVq3ieYGqiBrtj tBFv5epVvGK1zoQ+Rc+h5+dCWPwC2i3cXTUVf0woepF8mUXFcNhY+Eh8vvh1lxfD35z2CJeY txMcA44Lp06kArpWDjGJddd+OTmUkFWeYtAdaCpj/GItuJcQZkaaTeiHqPPrbvXM361rtvaw XFUzUlvoW1Sb7/SeE/BtWoxkeZOgsqouXPTjlFLapvLu5g9MPNimjkYqukASq/+e8MMKP+EE v3BAFVFGvNE3UlNRh+ppBqBUZiqkzg4q2hfeTjnivgChzXlvfTx9M6BJmuDnYAho4BA6vRh4 Dr7LYTLIwGjguIuuQcP2ENN+l32nidy154zCEp5/Rv4K8SYdVegrQ7rWiULgDz9VQWo2zAjo TgFKg3AE3ujDy4V2VndtkMRYpwwuilCDQ+Bpb5ixfbFyZ4oVGs6F3jhtWN5Uu43FhHSCqUv8 FCzl44AyGulVYU7hTQARAQABwsF8BBgBCgAmFiEEAExkfXVyz31yvbT7aZ2FCp9Be9gFAmZY +hkCGwwFCQWjmoAACgkQaZ2FCp9Be9hN3g/8CdNqlOfBZGCFNZ8Kf4tpRpeN3TGmekGRpohU bBMvHYiWW8SvmCgEuBokS+Lx3pyPJQCYZDXLCq47gsLdnhVcQ2ZKNCrr9yhrj6kHxe1Sqv1S MhxD8dBqW6CFe/mbiK9wEMDIqys7L0Xy/lgCFxZswlBW3eU2Zacdo0fDzLiJm9I0C9iPZzkJ gITjoqsiIi/5c3eCY2s2OENL9VPXiH1GPQfHZ23ouiMf+ojVZ7kycLjz+nFr5A14w/B7uHjz uL6tnA+AtGCredDne66LSK3HD0vC7569sZ/j8kGKjlUtC+zm0j03iPI6gi8YeCn9b4F8sLpB lBdlqo9BB+uqoM6F8zMfIfDsqjB0r/q7WeJaI8NKfFwNOGPuo93N+WUyBi2yYCXMOgBUifm0 T6Hbf3SHQpbA56wcKPWJqAC2iFaxNDowcJij9LtEqOlToCMtDBekDwchRvqrWN1mDXLg+av8 qH4kDzsqKX8zzTzfAWFxrkXA/kFpR3JsMzNmvextkN2kOLCCHkym0zz5Y3vxaYtbXG2wTrqJ 8WpkWIE8STUhQa9AkezgucXN7r6uSrzW8IQXxBInZwFIyBgM0f/fzyNqzThFT15QMrYUqhhW ZffO4PeNJOUYfXdH13A6rbU0y6xE7Okuoa01EqNi9yqyLA8gPgg/DhOpGtK8KokCsdYsTbk= In-Reply-To: <20251201085813.1616095-1-felix.moessbauer@siemens.com> Content-Type: text/plain; charset="UTF-8" X-ClientProxiedBy: FR0P281CA0172.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:b4::14) To AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS4PR10MB6181:EE_|AMDPR10MB9522:EE_ X-MS-Office365-Filtering-Correlation-Id: fcbe373c-da80-4f1a-2d87-08de30ba238b X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|366016|1800799024; X-Microsoft-Antispam-Message-Info: =?utf-8?B?SGlDNTJNOGtySlpYNmIxTTBYQ2lEdE40b0dxak52T055TzdEbENXd21RV2I1?= =?utf-8?B?UnpoR0QremFyNHU0OVplQW90Nzg2TngrU3R4NGdXU0JIMWFvekdaei9laUh3?= =?utf-8?B?YjViOHZTU1dpSDIyVTZSZW5hcVJmeXlvaWJ6RVZrSnJ4YnJqQmhXMnRPZ2RE?= =?utf-8?B?TmVveTRnb1NSZUl2NStsL0Vvd0t6RXY5R3N3Q2I3SU5qOHFaaUFnSitobWVD?= =?utf-8?B?Rm9PVHFEdCt3ZDkzNXU3ODgyd3hKVWx6UEZGNml6dEFtZ3lSZkhRNGpJRWRO?= =?utf-8?B?UytxT0ltaDRLUzVNTUdNSTVOejNoQVI1RUJWVjZJbVFmVlZkYVBIR1hIVHRG?= =?utf-8?B?aTVaVm8yNVRBVnNudUZQQlpxWG1yN1Y2U1R2V3B5N0dhS0ZsWXJkbnNRQUYr?= =?utf-8?B?bE85anc5Z2I4RS95LzJaejhPQ2xHbVg3T1dWdnhTZWJqeFRjV2RKWTlOWEtx?= =?utf-8?B?dFBWTHE0Q0JjL0JUcW9RVzVnbnlPWTREdjBUOU9wdHlNem4rTHF2cUY1cW83?= =?utf-8?B?NSs3UnNzOUlHR0l2V1dtYlp0MkpTaHViR2JoMW1kbkltT0xWV1VoV0pwUkhO?= =?utf-8?B?LzRSY2tjR0dad2JVQ2ZmM215T0kvZjNmcXRYeTQ0K2c0Wmd5NjlOU215MHpQ?= =?utf-8?B?NHVDMW5FU2F2c2haeU5jMlp2N0x0bVJjZDZkR1o1Y1lnYjFXQlphREFRYzZC?= =?utf-8?B?WGEwaWJyUm9vcHFQVHhJNTlMU0thZXJ4WlFUM29oQTh4UWdLSDhvampCM01h?= =?utf-8?B?dWxJdmhpazBZRUpGYVZEeU5vc2ZpUHovdkNlb1FPUVRvK3hzUzRKeExiRUdm?= =?utf-8?B?WUJqaEhRTGNNd2F3TnhpMmtsTHpHM0V2cEtUUWs1d01VZmdZaC9KZDZpN2M5?= =?utf-8?B?R09JOUJ1ZVg1ZTlUMnlYVE1QTURUUVBBd0x1ZnFONGJ5eElxaEY3Ukd1S3hS?= =?utf-8?B?VlZXeVdYVUUwb2tZRCs3Q01GQ1ZRb0o1Q1RMYkNmdW5IUlBCNjMxQUYzVmZu?= =?utf-8?B?ZGxwbjY3Q0ZRNXNIVGZScGZyUTJBdnk5dFlWUmtpTFpCVVNhUHB5cXlpcVVJ?= =?utf-8?B?clNDR0NsZzFKcDlzN1lXL2dPdDJUNlVHSjdsa3pwd2s5dlBVWU5BMGlDSklt?= =?utf-8?B?SGluM0U5MStYd0ZqTnhYMnB1N2RRVUxFTnkreFdlaDVWS3FzR01iNXBUYURS?= =?utf-8?B?V2pHY2t3NEVOeUVSajk0WFYrU3phTEs4bXJZaUhtbHFMcUZaM1BsRXh0ZnNl?= =?utf-8?B?UjNPZXpuUFJOWlMyRE1wUEQ3Qmg3NXo2d2RYVjRWVGhVVkJZSDU5OHhSaSsx?= =?utf-8?B?T3U1dEZxaTZabE1UL1dVUzM4Tzcwck5lRnNRSDAwSU5YNjhFM1RxVDZHb1Na?= =?utf-8?B?K3NyUjhjbUNMbDM5VjdsbkFRSjhUdkFEL0tqbm1yaHlUL3FiQnJ2SXZTRlAw?= =?utf-8?B?RnR4N3U2RE9GUU1TTU9HTUR6UW1kSzdnUEtsTHNVa3Nhdmg1L2VLR3N4OVJZ?= =?utf-8?B?aFYxTE51MjhRUldSenJYQkliaGsyQndOZkU1R09YQmRaZGFxTnk0enBNb1Fu?= =?utf-8?B?OUNlWVRxWDYwRzF1UTdUN2F2UVc5akpSZUIvTVlBODJqTk5TL1B3amFFMXlh?= =?utf-8?B?N0RwaVVtYmpCS1RscFYwc2w0aW0vOUtMZFpMY3g5NmM1NTdLZmNYVzlrR05Y?= =?utf-8?B?N0MzYUhjcTBPd1lpQ3NnL1V3WTdjajhjd0hudWdQZ3c0RGNBemI0b3RYWmZr?= =?utf-8?B?MXFhZkdLM3pWblU5OHMzWGZyTG82dWNKWDdoSVd3OTdYWGtWMGprdXkwOHJr?= =?utf-8?B?ZVhWTkVxZ0Z2ZWMxcngxNWQwcFBsSlNRdE1jcnFlN1VTR29nUTE2Nmp4OFlT?= =?utf-8?B?UmpiU2MrWWFiU2NVQUhkcm5Jbk9kcVdFR010NWtWSG9oMHc9PQ==?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?N3JnQmhvVkdUZXpsOVQ3VkZERlVsY3BnYVcyRVV0RFpVaCtSTHFFbGJYUG51?= =?utf-8?B?SDc0TUJlME9uTUU1ZTBjUURDQ0puVXdaeXg5K3JqZHNkYW83K0J4eFBOWmFZ?= =?utf-8?B?NUZFbDRiYWIzMWk3RDBWVHNDYktuRVhNU0dhSDNsMnVhUU14enRnQlVCWWNi?= =?utf-8?B?ckJhSnhMNmh3UFRwcnJQOFlaVU5mcHBFY3BxN1FpbzZlUFZPanBJRTdYRlB0?= =?utf-8?B?bkZWS3RsTXcxZnRWZi9QMHI1UjBucERSY20zNkE1aWZKTW9aOStEcndxNWtv?= =?utf-8?B?NmtwSkdRUFhkVmMwaU8yRUMxZElXbW96Qk5vOERwYUlSZEg0dzNWMHgxTjZw?= =?utf-8?B?L3V4NU8wdHIrWWtwYlE1bE5HZ1VKR0ErRkRMbVd6dkFsUXd3TXNvdGZldGZH?= =?utf-8?B?UXhIZmh3a0NkUzlzRjJLaFl2Y3phWHNEczBTSWNVbFNad0x4emxjNEEwUUZL?= =?utf-8?B?U00rQ0tLRkxGeXlYdndsRW1DTnplN1oraXRGL3pTR0NkaVRKOVc1U3F3Wllq?= =?utf-8?B?aU83SE56aitBSVBJUldjUi9NWko2OUVkSThnbTExUktGSDEwMURtcHY2d1hm?= =?utf-8?B?TVFKemFiUWRQb3JEQ2JUOGErTGthNC9paVIzVWFTdjBjMElGSFhQU1FiV0g5?= =?utf-8?B?dVpLVGNpd1dlbXhJRnRLNTFNSTFwUnorVldKUTJBZUdLRUlYMlNoaVlmTHlh?= =?utf-8?B?RTdJWkFPeXRQTlozR2FUaUJ5QW80UDVCZFl1V3lMcHEwZGNxTFBsWUhmQ05D?= =?utf-8?B?QVlJV3NxYk9DZXBnWnJISFAvc3R6RGJGWVgzeTlHMmZMdHZSSFdzYXFqNnY0?= =?utf-8?B?S0dtT0trMkNHRE5QMVRiUld3czdPVDJka3N2eUpZUDhDUnVTK1I5dXZqRXhK?= =?utf-8?B?MUJRRjBCN2wyYkxVcGlxTXhWTGlKRXdXQXNkRnp2RVBTMVNGdFlUb1JDK0w1?= =?utf-8?B?aU1iUWE3MXZGYnRLeStGVmRpRHg2TGw4WVdVaEcvanN5WVc4MU01NUdQOVc3?= =?utf-8?B?Y0NoNUl4Zk42bjRVaFVkNHhLaXE2QlpYc1Y1VjRYa2N5VTVLWElJY1JEMnFu?= =?utf-8?B?NFhmTW5OaVpIMFZ3TUNrTm8zcTBudHkwTjRLTTRuV2hTV2NhREVhMkF3Rmp3?= =?utf-8?B?OUI1TkNmZVY5VHhhZ2xpVEZTL2lwT1VGYWxVbktOOW12Q2pTdmQ4Ry80NEZ3?= =?utf-8?B?VnUwTlA0QnQ1TTArTTg3eS9BODVzdkt5TkNLUWNLVXRHMmZSSHVNSjdqSU9I?= =?utf-8?B?eVg4OCtnMnI2cEdPbGJHWEg4WkdPTW5oL0twOVhWblY5S2llQjNZODh2dWhi?= =?utf-8?B?YXEvRGM2aDdiR3AveWk5MklWaTk5Y2R1eGtCL2M3akQxYlY3emJCSDlpaXFz?= =?utf-8?B?Q0p4UGdQRUlIQ2tOL3ZYK0lBVUJEV3I3N2JkMnM1UUZDWTlXK2s5Wk5JQkJm?= =?utf-8?B?ZTlNbHZpaFJMK2UvbmdiV1JoZFIrVFFFNEhPdmhtS0lsOTdZUDBZbTFNdHBy?= =?utf-8?B?Y1lWTTlKSS9XQXFacXFlR0k4Ny91a0JzVlJHTWdtd0kyNkdKclFlY3FydUl0?= =?utf-8?B?NWFVZEhCUG1LMzZha20xVm5vcW9KdnpWWDJlVHd0RHM3bTBhanNYN3p2WHl4?= =?utf-8?B?QzBUSlJETE5Rb3h0SHU2VGczdjhtbHVmbFFsRmVTZ1lOSDFCUWNiQThrOEx2?= =?utf-8?B?cS82YWFQV3lYeUZiZlJkc1hxeHRsOUhGQ2xGNHAzUzVoOXIzMWMrRlJjQm90?= =?utf-8?B?SnpXZ2FHZzB0ejZ3bmxZSUE1NWw3cUc2Q3NwV216UEhGRTRPU1E0Zmd4b2FZ?= =?utf-8?B?ZTRJbHd6TUhmWjlnM3EyZ1RBMXlaWTJGZUFVdjlGaHBDM3pINFgzS2dYcWdR?= =?utf-8?B?NnRhcWk3M0hFU3FHV0dNcVEwdStBSTEvaDBlanc2eVZYK2Voa2VzVGcvVDhZ?= =?utf-8?B?OE5va28wZHN5MWpzQlI5c283WUIvWmUwR3N3L09mSkNQRmN2NS9ZYk4xbE9s?= =?utf-8?B?NlVSRzJKZThwaHk3ZHk2U2pVM0haRXRmSXlpYVppMmpxM2RCU2E3TnRoWWxM?= =?utf-8?B?OGdzMG15Um1EOWNOZmQxT3JEQkhzR3BiZWZLdUhETnE5UHpGRE80aGNpbFIx?= =?utf-8?Q?ScMWuSkip8/FktUTosFVBxqy3?= X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: fcbe373c-da80-4f1a-2d87-08de30ba238b X-MS-Exchange-CrossTenant-AuthSource: AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 01 Dec 2025 09:15:15.2927 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 2tfVetKkh1sWCWKeckhFCUZScVT5GJV/TT+WUKpHUHBc7F+w3GLAPEnNliaw9T7Ljxp3iOKnbzeFKqS5I4uiFg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AMDPR10MB9522 X-Original-Sender: jan.kiszka@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=WRaGyYh0; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of jan.kiszka@siemens.com designates 2a01:111:f403:c200::3 as permitted sender) smtp.mailfrom=jan.kiszka@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Jan Kiszka Reply-To: Jan Kiszka Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: N4mV/+yJgIDY On 01.12.25 09:58, Felix Moessbauer wrote: > This patchset adds proper SBOM generation in the two standard formats > SPDX and CycloneDX during the rootfs generation process. > > The generation is itself is handled by a SBOM generator `debsbom` [1] > which is developed as an open source project at Siemens. It is still > early in development, but it has enough features for what we require > in isar. The required dependencies which are not yet available as > Debian packages were minimally packaged directly in isar too. > > This is a followup of the previous RFC [2]. Since then the series has > changed a lot. The SBOM generation was moved from a simple OE lib to > `debsbom`. This also meant the introduction of a separate chroot was > necessary. The SBOM generation process was also moved from the image > step to the rootfs step, along with a lot of minor changes and > improvements. > > [1] https://github.com/siemens/debsbom > [2] https://groups.google.com/g/isar-users/c/8L-CF4BJY0I/m/p0N3o_zfAAAJ > > Changes since v5: > > - fix isar-image-ci on qemuamd64-bullseye (set IMAGER_BOM according to > machine changes made in image file) > - rebased onto next > > Changes since v4: > > - rebased onto next > - fix race condition on creation of ${DEPLOY_DIR_SBOM} (aka ${DEPLOY_DIR_IMAGE}) > > Changes since v3: > > - fix issue on external bullseye initramfs (we now disable sbom generation > on all unsupported distros rootfs instances) > - update debsbom to v0.4.0 > - rebased onto next > > Changes since v2: > > - fix issues when HOST_ARCH != DISTRO_ARCH on derived distributions > - update debsbom to v0.3.0, which fixes the Origin: bug reported in v2 > - generate SBOM for imager as well and create merged sbom of .wic image > - resend imager manifest + wic manifest patches to reduce conflicts > > Note, that the patches p1-p5 are most important as they add basic SBOM > support. The remaining patches address the imager + .wic bom part, > which also can be merged later on. > > Changes since v1: > > - remove tarball > - refactor packaging (auto-derive python dependencies) > - only build missing packages (varies on bookworm, trixie, noble) > - add ubuntu support > - only generate sboms for supported distributions (bookworm/jammy and > onwards) > - update debsbom (includes bug fixes and more information for source > packages) > > > Christoph Steiger (3): > meta: package python libraries for SBOM generation > meta: package python3-debsbom > meta: add SBOM generation with debsbom > > Felix Moessbauer (7): > refactor: move get_rootfs_distro from sdk into rootfs > override distro vendor in SBOM on Ubuntu > add support to add imager dependencies to BOM > wic: create uniform manifest describing all image components > qemuamd64: add IMAGER_BOM entries > imager: create SBOM of IMAGER_BOM packages > wic: create uniform SBOM describing all image components > > doc/user_manual.md | 1 + > meta-isar/conf/distro/ubuntu-common.inc | 2 + > meta-isar/conf/machine/qemuamd64.conf | 1 + > .../recipes-core/images/isar-image-ci.bb | 1 + > meta/classes/image-tools-extension.bbclass | 29 +++++++++ > meta/classes/image.bbclass | 7 ++ > meta/classes/imagetypes_wic.bbclass | 30 +++++++++ > meta/classes/initramfs.bbclass | 3 +- > meta/classes/rootfs.bbclass | 23 ++++++- > meta/classes/sbom.bbclass | 65 +++++++++++++++++++ New classes should go into the right category already, then rebasing is easier for whoever has to do it in the light of https://patchwork.isar-build.org/project/isar/list/?series=1780. Look at the dracut series. Jan -- Siemens AG, Foundational Technologies Linux Expert Center -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/20caede7-0708-4ed4-8aac-084bffaa6887%40siemens.com.