From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Fri, 24 Oct 2025 11:00:09 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-pl1-f190.google.com (mail-pl1-f190.google.com [209.85.214.190]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 59O9070k032751 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Fri, 24 Oct 2025 11:00:08 +0200 Received: by mail-pl1-f190.google.com with SMTP id d9443c01a7336-2904e9e0ef9sf36517355ad.3 for ; Fri, 24 Oct 2025 02:00:08 -0700 (PDT) ARC-Seal: i=3; a=rsa-sha256; t=1761296402; cv=pass; d=google.com; s=arc-20240605; b=Bq+cCHu47SobqNyujLxCBggwxK/PoC78PrjJau6DsPFe3X9nE+ReHzfWCrUa58vfXR dIDUiH2pc+vlcLftNw+BwomIbVJoUPWyyxMDkK8HmzF7bskxjMi6vaqc2Al/Z0bssliz x0RACqwMBbj0HuepovgnZU5Y9GICCsyR2UTTFQ+NJCQ0UU1z14+j7axvZKqEI/CY74Sg 5QqGUJCstxtg9qhzRQEV4x5kch1fHnwnlYIs8DhgfWi9XRbiwjim2S+mAj2N3gX03ary /vV0jfV0XlI+UFKy17ZmYlGUAjbpiTABSR88wEmr4xYUXpxCgFUFE2bljwphu4chINwI DNPg== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature; bh=/KRuTDnX+p75grh+u5EqtdFBJDUVh75VhH6bbQSzNL8=; fh=7Kk3RdkiJfImJPJm1Cb5Q+o1OasmN+vDQ4EG+AGLllQ=; b=e8udDeWDSKKtEsXLK2dkfTvb2tBtcuwIuzuqmXl849tGqg3DmJNKJYns2JfdduLB9H LhCvCuRDROIfYu/Be79K8m5XQp28r3Vws6DsAeVEmWgAQpIa7ZJvcTUMr1XwzHwXs1wM 6yQFrlR67PtWtLPUBC1OOpHCdwvyLWzTnunFuM+fjHE2HbM6tkzGrX8rOvOdkeLqrF5v wi839JsxTzfPnlkmVCeywHKIWaB+FsGnVJ5DtXv/OUY59Xu4CHr5Tl5cvw/ptj88W9zF kT+rR/tArUxaC3JfUIg+OlTxX6tDNjYI9qtBZxq/vNyB46jn9aGsc4uIfPc96GpkXOs3 CJxQ==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=sSjRB4LD; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1761296402; x=1761901202; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:from:to:cc:subject:date:message-id :reply-to; bh=/KRuTDnX+p75grh+u5EqtdFBJDUVh75VhH6bbQSzNL8=; b=Dqdt0AMLJ7YNgNr9t9vJ2fpyfSK8zBxIGCqS47pGzSw0nYlIn+4chECioN/yi6AzbH uRUNQ0za6mzz/5jhWMEeu86x2uis0zIhynq/69Rk8ErEamTG3DdM1X4MZ4NNIVfNWc18 yVvOyj9xJ29qo8xGOGHYfBEvHiUl4aOBuHx2XORDq1ONewhP8rQYtjF65EMgdVqupPLt hH4v7DBFH+iAUBddeWSdzNGnwqQ2Ibp+19tk5pywGnZSgCUlk1Rb8mPD4r8hnenECELE jbUsIAlQGq3NOw9sxsxvxR3MCXiEfv/3qn6o8ZotqXygHuToCbFT9mGbN6bn2dtzyU8P oVvQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1761296402; x=1761901202; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:x-beenthere:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=/KRuTDnX+p75grh+u5EqtdFBJDUVh75VhH6bbQSzNL8=; b=HJ4VW7ePobMyZNblauYe10WcCQdY2Z8oqDJRtw/KucbBgrEwA7/UJUoShWzy6PvO0h JhydmAqKfkFemd73asFs9O/ECtMATAfUND8oflx3hmIPpageGIqz/dXyf3qRBhpfICnl MgoialHY/RhERgrIgssC1y/009QerY0aH8LYqphwZU8jrp1XMILwsoBREr/638GJTYBd OkeygdhDjqH5nTOs+kLA2lVPL6OwX8b9QQ/UScdfjhzKkxJrMdSa+9I5lTJ/nMTvsBDe JWnQr43Pz8E2NEkU1LyRSOCAJwUUBbCeI1+QPKd6ZvI8OBi53yAwbYFqlkOZd32CJCMq dVKg== X-Forwarded-Encrypted: i=3; AJvYcCWbUo+sPfntdgGBNrYEKgOdkkYzqIfgVeLQYOyuI/OOGcEELyLHpiJKkNgvytrP2FDh/s1o@ilbers.de X-Gm-Message-State: AOJu0YztVl+PyBeIqZ/ICWZDPfXoGZCvHDrV28Ed2IKeEzyeRme45BsJ 9QVoWp4QczvhvfMzUpankUZuxImrztq43Fhew4entpyRppMu1UpVaagI X-Google-Smtp-Source: AGHT+IH4Qy3Ep6vjdzacTFHiq5jeNG8oivU3sVTl/NS5RCHUgQCNReGHGpq9AMeskv2dLwFB8bBeTw== X-Received: by 2002:a17:903:228f:b0:24c:ea17:e322 with SMTP id d9443c01a7336-290c9c89cbemr341726515ad.3.1761296401415; Fri, 24 Oct 2025 02:00:01 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+a1LOZ/tV/gkqh/rlPymHbB0P07ZXfgROqR+bKTnev0ZA==" Received: by 2002:a17:902:7898:b0:268:589:fe0b with SMTP id d9443c01a7336-2946c7694a3ls15631095ad.0.-pod-prod-06-us; Fri, 24 Oct 2025 01:59:59 -0700 (PDT) X-Received: by 2002:a17:902:e88e:b0:28d:18d3:46ca with SMTP id d9443c01a7336-290cb65ca07mr366222445ad.49.1761296399640; Fri, 24 Oct 2025 01:59:59 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1761296399; cv=pass; d=google.com; s=arc-20240605; b=dk+7mnIyhwE42PK0ZgnOlXplbegAka4Xd0l6bn6OHdLmgKQtMo/4B5K9wnFzSMHSch WkdvXdaIfLOghjt6KxoxV11QiNJjWtkYllPBKxcng1zA9R+8CbEJSZlP5dIMMIUyKBuY TIodrnc1Tv9GYBYcKDulqHA2iuBw4fC5I1lss43mRWRQY0l3jsjNI1aeB2vD3rk+AWrh SXaQ4lpSiWzCTCXgbFhUqZ55Pt+fECCaznnnXJ9qlqHV6V/pqFtVjsSoMLXhi5eVTFgl 86PgEgEgsdmhVdCdV9nmmtMJQuGKoqv8pid90FWlPLFZezxNyQrjkERBk+6EBd4Sw/FK 38cg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:content-id:user-agent :content-language:accept-language:in-reply-to:references:message-id :date:thread-index:thread-topic:subject:cc:to:from:dkim-signature; bh=Mz/t2E/XWAtl9mYM87OnVDz0JGCctR41uwL4QSU81rA=; fh=wGzPg+eVKbk73KO7k2qlaV7Xuqkr7NxPnmnvifUfBTQ=; b=XYYS8oSX8EP5wS7lg0jAgmn+8q9LbOEdnwGWozmDde3XYbWWq9GOAD+fk/ojHe+Lyg U3ZX27X3fcUrboqb8f5yDKvVA+o8cOLXKY5V/tfwVsrg1Rpretf7w8+tgCkDDZUBtjR+ Y5BlRzXOaOBZn/aHRMaqg7z3oqlz4iGlpXM99CqAp26xyyA4AUC79IVyYEsNFU/3sr+0 42rTU6qaq+DL1YwXlrFncwwuvkl5V8F7JqQb6v81pZA1TY6XBeUB1WFt/lDyh5Gq4Pt5 XhL5T9zcnn1QwJZd8uP4QvU8K1eTaaOmq1ICCjTUsNTApzJAa0W8A4O83tC0jOsdBocN rlTQ==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=sSjRB4LD; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from AM0PR02CU008.outbound.protection.outlook.com (mail-westeuropeazlp170130006.outbound.protection.outlook.com. [2a01:111:f403:c201::6]) by gmr-mx.google.com with ESMTPS id d9443c01a7336-2946deaf76fsi3028955ad.6.2025.10.24.01.59.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 24 Oct 2025 01:59:59 -0700 (PDT) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) client-ip=2a01:111:f403:c201::6; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=myLsWBHI3ugygMWofJ4ySjM7PqckgD8sG2x4Hdi194siFFGzenFl9dwTiQGRNqvfo3RUuG/0MwFUe05Ghkp/742hzxW2ZKqC3YnL2HfobNNYOjumhVsongIm+3azeu9p2Rsppt2o96MRhmO0yki3H7XbxkgIzhqRRjwyEjqIf5HeXKGjRhRgyOTlhvhoXqjfUAf8+9uCzYnZuEiwy6F7cGXA2YVwKWqa85M384cVhWNC74awrBbQdD2wPTUYknr0n6iWWinMVF8ITqwTcNoIfsv9g9PDafJz3JljHA8zik0+tMlvqeImihFmzvwGKU7JaQGXjSKSaFORH+DjG0KemQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Mz/t2E/XWAtl9mYM87OnVDz0JGCctR41uwL4QSU81rA=; b=bfElYmaQEwdEGdd8NqQiMOWbdP1wrsYJcMXHdiDBMXMeka76Na2FwtiUlBPVi+ACZXIE0KC2fT0KRweIYwY4cSwcPnMJ22KbhpiQJzgY37R9SZpKixBl5d3M/dzndwB+87+Ksg34YVFNKYSxMs1GH0vFMK85Ilx//pZ0K19P8vQuFLqjnie3kuMqwaZuybH/rQDOkK3T9YHQpKnB9BiMj/MSiZL2h15qZLZ/53k7xfvE2jUEhDT3iE513wufiQ5NCx8Y2qg8d+sHiN7oy3bnd0GCSmZhXz+xnWhPnAVJHGa9m7qj0cRR2JFYC1VsrxEtGNydTu6xBctyMztYNxpF7Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) by PA1PR10MB8644.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:453::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9253.13; Fri, 24 Oct 2025 08:59:57 +0000 Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe]) by DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe%4]) with mapi id 15.20.9253.011; Fri, 24 Oct 2025 08:59:57 +0000 From: "'MOESSBAUER, Felix' via isar-users" To: "isar-users@googlegroups.com" , "Bouska, Zdenek" CC: "Steiger, Christoph" , "cedric.hombourger@siemens.com" , "Kiszka, Jan" Subject: Re: [PATCH v3 00/10] Add SBOM generation with debsbom Thread-Topic: [PATCH v3 00/10] Add SBOM generation with debsbom Thread-Index: AQHcQ2oQNyvOicM6EUGZpxerjoGlHLTQ+tyAgAAHcgA= Date: Fri, 24 Oct 2025 08:59:57 +0000 Message-ID: <5762df73039c652fd3a0d82b012361d76e1b104c.camel@siemens.com> References: <20251022153921.2494749-1-felix.moessbauer@siemens.com> In-Reply-To: Accept-Language: de-DE, en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: user-agent: Evolution 3.56.2-5 x-ms-publictraffictype: Email x-ms-traffictypediagnostic: DU0PR10MB6828:EE_|PA1PR10MB8644:EE_ x-ms-office365-filtering-correlation-id: 46477c6e-3b87-453c-d488-08de12dbb4ad x-ms-exchange-atpmessageproperties: SA x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|10070799003|376014|38070700021; x-microsoft-antispam-message-info: =?utf-8?B?d25TTU10d0pmMk1NWnJZeUswc284MGxiOUJFR1hOYzgyR0ZpWnNycitLZDli?= =?utf-8?B?ZjROem5yY29oRXpUaTdrSW13bTlja0UyMXUrWHVKOG5IK0NiTEFmK1NlVGwv?= =?utf-8?B?L1VYYTBXTUtKaHg0YWNtUUlPYktiM1JUT3JSVUJlRHhla2RPdTdpczdMdGhl?= =?utf-8?B?d1cyUi8zdEpEOTJ4bzhLdXQ5RzZmK24zOXZndE5lRm8zNEVDbTQ4WFFYdTlR?= =?utf-8?B?eXlieFRmVlRzdFJMVVpmanFyREVQdThVM2pNUllXVmhobmtjNEI4WC8rWXZr?= =?utf-8?B?ZWZSbWUvMExkcFZSUkdDdmVvZXZnTUJKODhla2VKbzk5cGh6ajhHcjRnRWVJ?= =?utf-8?B?eEZVcjNrOFVWcFJSMEVIRGlka2RTdWhNcFZrQzl1S1o4VjdjSjVQSi9YZ3E2?= =?utf-8?B?ZklmTTFXSWk5T1pUaGJLQlVPUjhaTEx4TjFhNWc4STNPT3hyejRXWVlQMzZk?= =?utf-8?B?Q3dHZXY2TWx0ZnZvS2ZaOVAvU29rVTcvWU1WU2ozRXFMODIreHZWUDlLSG9S?= =?utf-8?B?eWRyM3BDUlI2UnNyWTlyMEhaRHk2ZmF3TUd6ZGs2eTNUTVRKYks2elpOYjdM?= =?utf-8?B?QU1qc2wwZlF4MWhFNkdLSGlUUDNFdUh6SVdOa3NmbFRyT1p1MGR6WUxQSzFh?= =?utf-8?B?TVNUWWptaGJJZElNbElBbHJjYWFKZEVVVUUyN1dENXJmeDNod05QbHhPMDY4?= =?utf-8?B?a0xiUU9wQnIyd2ZDaTlhakZkZE9tcmdNRkVFcDg0NTcyOENPeXliVE9JeXFK?= =?utf-8?B?dlpFcUx6ZjI3ZEpCSVhqTTU5YzQ5NzFFbEVZUE04Q3NiRXlvNGFuUGZwdm5p?= =?utf-8?B?VDh5bkU4QnBSZG1ET0U2dm15eTNnRVlZVFZibjlhdFY1OFdYMXcya2lQQ2Q5?= =?utf-8?B?UEJZbHBtUlFBS0RQdUNiMGdFZENENXAyUnUyViswMjJSdHAxMGJQZkpTQ2pt?= =?utf-8?B?MG02T2E3TlY2dnpPbDFDc2R3VmxxVUdQd05mamlQL1FuS1lNVDBYMUdySmgz?= =?utf-8?B?S3Mwcll3azd2UDl0V1RSUi96d2R1YXlHNTZSVTh3QlVScHFyZm1SUlZDZGEx?= =?utf-8?B?d1F0bTVqMVpqM3UwV1FlcnMxd1l5WTFHTWxwUVhUazJYM2ZES1lxcldseGs5?= =?utf-8?B?QnhJdDFaZXl2VTlCbW5hY3RGMVZBcSt6RHQwMG9sTVQyQkdLMTkycnZoN3NR?= =?utf-8?B?TTJNV21sdmo5T212bVhsQ1R2WmhndldsRXdaVHpjTVVqVG1qYjVlYUNIYzJB?= =?utf-8?B?Zk1hN1d5b0lycjcwRGx3R0pqMWY2NTJWNDVvYXVPOHZTamkvYm1yMCtLd2lW?= =?utf-8?B?Tm15ZnpRMEl2c2NZQlo1alNQVkgyZVVtWENEZ05Ub3JlcTFnVGJxOTlJc2Z1?= =?utf-8?B?TklLNVZETGVkRW96U1JUZkNYRXlzaC9qU3M2M2tmMHRDQ2Z0azRhR0ZKeVpQ?= =?utf-8?B?U0JiZGFSZVpYYTRRRGNiQ0pjVFROZTZqTlB5dERSVVBPZTBTMW1MeDh2R1RY?= =?utf-8?B?YVhuTmhYUHVNcUhwSnRXeitaMFM0Q21IcHczTGYyNTdDT2kwVXNyU2l1cXMv?= =?utf-8?B?dTZKeTQvWVFXbDFqVXRndzBOWXhsOEIvYkhXT3ZrU0FQKzEra0c3TmJDdTNX?= =?utf-8?B?NGJJaWczbDYyeThuWFRjbXJCanoyRE41VkJUQ1FuMzRkMmV3UGsxK3RYSVk2?= =?utf-8?B?UXBWU0F3K01CZFNnbnU5Sko5ZXpwcnFta0ZyaCtxMFJtTXZoOHVLR2c0d1pS?= =?utf-8?B?Y0JYRU9XaXhIRjdhU3hGNm54bVNDcFNoT0JWeFpNUW1adnlUK2QzN3c0dVAz?= =?utf-8?B?TU0vWkRudjB5SU9UakxXaDhNOHpBNyttMWdKUWZQYU5MV1BHR3g3b0t3Wm5a?= =?utf-8?B?b3NML3RLSkZCajlyb1FpUXZ0eDl1YnZ5WjMxTVRBN3hyRHBuWnNrOUFyUTBS?= =?utf-8?B?em1ybVdtVDRwRE43K2pDSXFCK1VJeFBjdEdzTms4WitoQzVTRGxJOTFBa1NR?= =?utf-8?B?ZlQrVmZSRVNHUkt0WVJKZVVaNjhnZlFPclN5dEY4V3Q2V2xlRnJWR3BnUWVh?= =?utf-8?Q?CyFfw/?= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(10070799003)(376014)(38070700021);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?utf-8?B?NzFBTjJGZlpxTnFEZTlLSDN1VjVpdXZDaW5yTzZ4K2J4VElTdnNqUmxVT3Zh?= =?utf-8?B?dXhHby9wYyt2c2ZqOUxXYmlKYys4cWRlZ0o2U2hpWmc1QWR2eDYwb1Q4b0dt?= =?utf-8?B?TG9kY2FrQW1DOGx5S1VraTFhN0hvWHd5UzdLVFYweFB6UEl2b2MzbnptVTVL?= =?utf-8?B?Smw3S0JpWStJaXdZQXpFWml1V25yeEFKTFZ0d2NjcEEyOHF4enNZbHhKYnhR?= =?utf-8?B?VHQ5Y0w3WnFJYVZ1RFVDRjNKRGxHNGM1Z01nVERvNFhBYWQ2UGYycTNEWk9r?= =?utf-8?B?ZlZkY3hTNkhrcmd3TTZpaHpVSmt4Rkczdzh5Z3VVczZGWW0zdU93SnB2aTBG?= =?utf-8?B?Ukd4MGRSUzFDSlFkVzJIbzBjcGcrOXk1VFFOaW5NTmFLak9oVzNkMEZZOTBT?= =?utf-8?B?eTFZM05xTUxEUnptekFETWpSalJBMHlMRDh5S09qbnA4ZE0wOWJDcG5kVWh5?= =?utf-8?B?MTlQeGl4TFBRT1hoRHpMVktEekVQUUtVbGdkZkl5c1BucURONHpMcUZFdlhr?= =?utf-8?B?RzFmM2I5aWdJSkx1ZDhPNzh6NE5rU2Z0R2VDVC9oZTJMWTR5eVlVT3Q0TS9D?= =?utf-8?B?Z1pvdTlPMHQxYlkwdHIvS1ZwUko0MHZyODFDcy95QkV4aWZmZmxyeWVKM3o1?= =?utf-8?B?d0wzU3pVU0hneXl3Z3RFWFFySVZkSVdvRzFjcHdDMTYzT2ZQZHpIL1dXWnQ1?= =?utf-8?B?M0NBbi9nS1lteU4wL2MwWjY2MGVaZHRmWnNLZDNnczRDUGRwSndGSCtodWFp?= =?utf-8?B?N1JZMlk3dW91TkVtc2dtZDUrbVhhN2kxYThpb0U1bG1tQ3c4UnpNdmhOSEJZ?= =?utf-8?B?Wml1NTZscTlEVHA3ait3R04wLzNNMkQvN2tGdEMwOUNML0sycUVXRU5lc2RG?= =?utf-8?B?dXViMHJtc2ZMRkxtNWpZaHllOXlZQ1VsdXdNY0VJNnpYaTVJVFZFZ1Rzbktv?= =?utf-8?B?VDVVcDNaRHBNUmVvRjhNQUpWRm9XamYvZnlRUVZXQ2MyUk1sYlhFSVVSdncw?= =?utf-8?B?Q3FNbGhwajJuMzBmcDJlMlk1c2VROUVLZHE3TUhYZkFUck9ZNFVMYURLZitQ?= =?utf-8?B?U2hXR0ZXT0RTMzJDSkhzOHdNZlhQbVV2Y2wwSVZDZFQ1Sk13NUMyaFVhZnZj?= =?utf-8?B?blRzblN1Qk9VaWkrTHF5WXB3NUZoWTJQQUhqaFlSeFdpaHNEVmJJd0tkb0No?= =?utf-8?B?endhNkovK21CY0FDdU9TWjB6L01qTEVQSEU3K0lmekk0RTgwOW5sNzUvOW13?= =?utf-8?B?cFBDcS9aYVpxN2FjTGRHOWE5WjBGQy9LSmF1dnVWM0FBY2YrVExrVHRJbDlS?= =?utf-8?B?WkRWRXNuYnRTd1B4amtXeEh4NlQzWHVDU1I1MGUxc1F0Z1R5OWR0Rkc3T1FH?= =?utf-8?B?WVdFdEJleUFNdGJEaG9ZTjBFYjRjTkl0UkovV0hEZi9kODBCQkt1U1VmSkI5?= =?utf-8?B?WXBCN1dnUktPaFdRODNHaUlnTjhHVlBMTmhwYjlKcWlQanRMTXF2dkU3WGNH?= =?utf-8?B?dDdFYS85R3l0Mmt2ckROU2FCNjNvNDBRQUVMQWNhS2lYY09kcnRkZHkwYUpW?= =?utf-8?B?eGUzaVR4bEZLOGNCMEJDQkc0Z1M0QkV2Q3lhRFlJZUN4Nnh0dFhTazhQTGZi?= =?utf-8?B?dGp6YkRhaTUwaVlDbUVzWUd2b2J0SEg3bEs1Q3RVc2pURU1lYlR5WXlWem1a?= =?utf-8?B?dHY2S1ZzT1FVS3laV29FYVphb2ZQR1J4N3hTdEhaeTh5aUZiR2FYeHVXL2to?= =?utf-8?B?dnpCN3libFRwSDF4SDlKYUJlU3lGQVYwMlYvYzd2cDRKUStmTXkwakkyK0Z4?= =?utf-8?B?dEQxWE5vWHViU2VrT2NmUFVNYWNrOWY5ZXo0c1ErN3ZkdjJGckR2RHNla01u?= =?utf-8?B?L0krTHNRZjNhTTl3SUF0eUhFK1BnSEF2OFJNekdqOFdOL0VkZGE2SHh1UGdO?= =?utf-8?B?UDEzUlNpTEwrLzg4WlRRUHB2T0p4RDRrdWtHdmFob1kxcnl0c1lENDRZQW15?= =?utf-8?B?THEzZEFTekprL0xQbThDTHRmNStCTFNvbWJHMXgwdWFYa2ZVYVpzRU1hMXBh?= =?utf-8?B?SVFXMG4wOTRyRW5ZZ0w2WjQ3TlRndmJneXlHdTBCcjlRbEk0RE5GTWxHT3Vu?= =?utf-8?B?R2paVFQwRUJyaGVYZi85UzFya3QvTkhHZlVob1lEUjBUQ3JMTkIvbkJhaURH?= =?utf-8?B?ci81ZUZOTS8wM3JxYzBZdUxXZVBGTm0zR1U0MWczRjdzYTZvblhpVG9FVENa?= =?utf-8?B?aFNScUNqQmpoVzg3Z1JYcmlWS1NBPT0=?= Content-Type: text/plain; charset="UTF-8" Content-ID: <65B355BFD7606B4FA900441FD017E76D@EURPRD10.PROD.OUTLOOK.COM> Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-Network-Message-Id: 46477c6e-3b87-453c-d488-08de12dbb4ad X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Oct 2025 08:59:57.1560 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: rmBCS8uP4gU+PmkKidB0D54aY9P35Ub1KgOgBOHhz+7F3XtYVi0FWL1+bWBchciVGvElMLNXLDu9wAguVc7khIAkUZFxQknMRu15wT+rYQU= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1PR10MB8644 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=sSjRB4LD; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: "MOESSBAUER, Felix" Reply-To: "MOESSBAUER, Felix" Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: CVk2BKOVbO8q On Fri, 2025-10-24 at 08:33 +0000, Bou=C5=A1ka, Zden=C4=9Bk (FT D EU CZ PDS= 1 ICC 1) wrote: > Felix Moessbauer wrote on Sent: Wednesday, October 22, 2025 5:39 PM > > This patchset adds proper SBOM generation in the two standard formats > > SPDX and CycloneDX during the rootfs generation process. >=20 > I have two warnings when downloading based on generated sbom by > debsbom --progress download --outdir downloads --sources isar-image-base-= debian-trixie-qemuamd64.wic.cdx.json >=20 > "WARNING:debsbom.download.resolver:no sha256 digest for linux-mainline@6.= 17.2+r0. Lookup will be imprecise" > I guess mainline kernel and other packages built from source are not yet = fully supported.=20 Hi, this means that the package was not found in the apt-cache. Did you try this series with a fresh build-dir (sstate cache is ok)? Unfortunately our rootfs_postprocess_commands are not idempotent and by that a partial rebuild of only the sbom infrastructure runs the debsbom tool in an rootfs where the apt cache was already dropped. Anyways, the debsbom tool also supports the custom / rebuilt packages, but these will simply not be found on the snapshot mirror. The error above indicates, that precise information in the SBOM is missing - indicating that the apt cache was missing at time of creating the sbom. > But SHA256 for sources with my patches could be computed in the future if= I am not missing something. Right? > I understand, that I can't then look them up in Debian, but at least the = SBOM > would represent the sources with the patches in the SHA256 and it would b= e possible to verify if I have correct sources. >=20 > "WARNING:debsbom.download.resolver:no sha256 digest for openssl@3.5.1-1+d= eb13u1. Lookup will be imprecise" > Not sure why SHA256 is missing in sbom for openssl. I use it without any = change from trixie. This time, the warning comes from a package created from a built_using relation which is not in the apt-cache. I observed the same in a bookworm container (where I ran an apt-update before). Unfortunately, the built-using relation does not encode any checksums, but we also have no easy way to annotate that a package was created from a built_using relation. This topic is currently also discussed in [1]. Citing: Source packages referenced in built_using only have name and version information, but no checksum (and they often cannot be found in the=C2=A0 apt cache) Yeah, that feels bad in the abstract. A lot of .buildinfo and built-using information (and the signature!) is only valid at the point in time of building/ingestion.=20 [1] https://lists.debian.org/debian-snapshot/2025/10/msg00004.html Best regards, Felix >=20 > Thank you, I like it! > Zdenek Bouska >=20 > --=20 > Siemens, s.r.o > Foundational Technologies --=20 Siemens AG Linux Expert Center Friedrich-Ludwig-Bauer-Str. 3 85748 Garching, Germany --=20 You received this message because you are subscribed to the Google Groups "= isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/= 5762df73039c652fd3a0d82b012361d76e1b104c.camel%40siemens.com.