From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Mon, 27 Oct 2025 10:24:53 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-pg1-f184.google.com (mail-pg1-f184.google.com [209.85.215.184]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 59R9OpXQ018014 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 27 Oct 2025 10:24:52 +0100 Received: by mail-pg1-f184.google.com with SMTP id 41be03b00d2f7-b6cd4d3a441sf3464974a12.0 for ; Mon, 27 Oct 2025 02:24:52 -0700 (PDT) ARC-Seal: i=3; a=rsa-sha256; t=1761557085; cv=pass; d=google.com; s=arc-20240605; b=W8KrfBrCV8Tx98JyXvhND5zP9mJkBm11g1RBXtPTLBbQimrL8h8CkpZbmQ8nRUSxST uTCn2l0L0EMoF0Z1FLkewA3eKnAu78Ex5PADHmXKFGO210LuW6hXo2PYExdaQ/lEqzVW h7w+GKD0zqhsICEQAZk19LlFtSOsM+vlwkbzjUvU159wi3gSSaR3xCAfp++6G4SrTRux xej+pcHPcVx1muAnhTw4+wLqNRcVWAUTMoKzB0JFTQfCJdfzlJxqm80Bckipv8fkpn6T wzqOx+ZAA/i8S4E+UsoToiMq6OPkSTmJfhhsM4FRozrT7HbTk1YWEvSeJlSYgJOeXvdx lDxQ== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature; bh=jBtHTFZRkyB0i/sTwWhiSaw9YiscvF/q2nKcEC5I5/g=; fh=kf0zWt8g/qdGz3NI/skyPz/MN/PbhAPdd+GI68KrMeM=; b=jqa1Wm8InLdj8ciqZTUASO6JpJAZYLINbIsPPmp7KZh3WKRYzNbI7supMr9T5VKXqK 9wZFZDEqyrh8S1ss/Yb8GPbu8x/kR4FMH7AeKYr1I8h/dyzzi0BuvTR5Sw9onN7Xoq7j Kq69HBtVHql8Ln5/67XLMWMIOr9q/d4qRs185cGAwqt1sDQ+m+nkooKl+blC+pZFYB63 lvylyKm9TPdYLEv9yN4DlLeKXnsRd5gd0xVb6i2NQTQfEz27qRA4daB0CTtTU7/rIyB7 RBc/xS4j1B0aeYEek1N9tR8yE8nbwT+ZaubMFeil2DoRjohY0aF4jJA/ymZI1a/WZVnc d4ZA==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=dKake0OW; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1761557085; x=1762161885; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:from:to:cc:subject:date:message-id :reply-to; bh=jBtHTFZRkyB0i/sTwWhiSaw9YiscvF/q2nKcEC5I5/g=; b=sjkCbY4Z3wzNGCn9SiJH2W0W+FtsHeO1WUENaxQdL8mVLi8KlKh9nXO6R7sEYa9PK/ /JB+Ai1oo6tdrZxl73n5Afp25dHlIBIwWmzt/Gz3sLIn0UgIbzarBLZGpzYv3TrrwkEO buj0ZLvNeWUIlUK8ON06v1QlbTNPZPQybJo5LaOHeyqOPf+7ATPhNm5slA5KAsYfEmZ8 nXwcZJ/SKntcGPc4cBi3qp9t0xtiVfvPbQ8J3rgcKcozkDGap+4NbhA3m9WKlt+aMQHg JhwQnzpIwAW9Bku1EsNjGGRyL5LjZTNvcHOSG38wj17E9s00snjefqU8r3e6D2qlZIb/ Vk+g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1761557085; x=1762161885; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:x-beenthere:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=jBtHTFZRkyB0i/sTwWhiSaw9YiscvF/q2nKcEC5I5/g=; b=wcwpu+qvzjKBsG+1GJoOxS+ld+lf6KIIAN51dhi21QmEh01EzUDfLfBCTCMDfBYGBJ /VQtb0ZbdDG2UawS06u70gZpQ2On+28e2G0U+LslZ2JVJie7hTewGhwyKNu4AT+RQGfq 7S2UeM6xCqvVtjNpyObIgIcpPFzzO8cwfFTPJOaNHm74miv558UdFwzoLD7Iapz2r3q9 r5q4t/vJigovsilEf0btGw69UoUU06DmbwTJ7SP9M1UOo00gR+avfUSwHpwgPPQu0A69 rA3r+JRmaWtjtWhG+cIQkLADtY9Ijyd2Nsu7NlvulKaZcDPeW1WEZggyXY5pUuWnLCGY iCvw== X-Forwarded-Encrypted: i=3; AJvYcCV6YoJh3zY15z/ZtU0hsihCcccr3o/8TlhujzXDgPNWWT0qDOpY8KKXdrfnVi9SecNcr5qM@ilbers.de X-Gm-Message-State: AOJu0Ywh4IKjbaBEVogFSWe7d//FAIXZpyy9vBVmRLz1Q/aAxzq5hht3 oXDRJasARFisBOGvJ5rqxgndN9G2VFwslOxUv1wNeva+qXyjEo1u2SH2 X-Google-Smtp-Source: AGHT+IF9+VI21VPmFFPnDe7II/L0NwRsQqUaP1eFSPfhZvQ4Qui4Et8qiP6R/GZmwK5jfqjl7G+bDg== X-Received: by 2002:a05:6a21:6d88:b0:32a:745f:beed with SMTP id adf61e73a8af0-33db47e0a1amr12771623637.26.1761557085241; Mon, 27 Oct 2025 02:24:45 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+YD8PJl35cpYuKt8xMo2XCFzVWZnzQ+3Mhw30C7JoUQ6Q==" Received: by 2002:a05:6a00:a17:b0:772:69d1:8e23 with SMTP id d2e1a72fcca58-7a4178514f9ls786311b3a.0.-pod-prod-00-us-canary; Mon, 27 Oct 2025 02:24:43 -0700 (PDT) X-Received: by 2002:a05:6a20:6a1a:b0:334:8d0b:6642 with SMTP id adf61e73a8af0-33db55f0d01mr13032830637.26.1761557083351; Mon, 27 Oct 2025 02:24:43 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1761557083; cv=pass; d=google.com; s=arc-20240605; b=glcfwMF0Px1Cvx/GbDoxMK8MHPVc5Zh67p9koTj++1vwuln3/arFsXyJgqGuP0MCBP 4qX1bmV+wFI4qPp3HlUpjnBjwDeNFX7dOPkIPgs+PRGP8knNJWY2lfqsHbkfM0iMl76c WzJTuFhYZz2vkfAUhgD7gynD3Z/3wJbiElkQWKiyM4HFCmmX15Pninfs6OptgIvhlDSc KoHwQXtWcsnoGKS3ctKwp9LDf5/snz09mC9f4u+RIrqeLDWf7zrlhQZ4d7l89h+J+Frq 513BNhqMCy+Mbo1fLqRnsqneI/cBJXj+tz9mM5hCaBo2z04OeYE+Mos3IfGtotxqwodk D+oA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:content-id:user-agent :content-language:accept-language:in-reply-to:references:message-id :date:thread-index:thread-topic:subject:cc:to:from:dkim-signature; bh=gKFQa2A321zE7NJ/Ka4/AqQ75vN06yxtGnHsH0CUf/M=; fh=wGzPg+eVKbk73KO7k2qlaV7Xuqkr7NxPnmnvifUfBTQ=; b=UYOrUq/2L/AOq+OJEVBoWjU1mN5++BtqVEdS818Adc94NIeGy5+/PfRdhnN1eCUJc8 mQHm2cBiH9Q1zHdpWvZBXNh7vMOTGu+619kiQu7H8GTKQ+j6s9KENqshFx0Zo9a5CcAw W9fAYoSK1vdlnFCvWJjBg4RyN9MjweGWw8hkHEkWIquRpOiQjsSIA6B1V6AQJ/v+S6sE NcbrIOc09mMxFk+X05riGYABbuphcm07nxttJrVTU7zPlJvDyufciRVN/T4NNP1Ok+tr PltbnU6SUT5sgoD9ItRhX7ZuMJ4Gka0CZyYpUfYjiaCVxdDyo3WqK8nObCvPhihdtbtB d3Kw==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=dKake0OW; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from AM0PR02CU008.outbound.protection.outlook.com (mail-westeuropeazlp170130006.outbound.protection.outlook.com. [2a01:111:f403:c201::6]) by gmr-mx.google.com with ESMTPS id 41be03b00d2f7-b71fdd6da2esi279580a12.4.2025.10.27.02.24.42 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 27 Oct 2025 02:24:43 -0700 (PDT) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) client-ip=2a01:111:f403:c201::6; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=flN90BAEqfiz4aHNc6uIXryKsdcam6qXGaV902AWlPdky3CWUWx+cIrHV5YsLqWxujFYA/eQFGfk0ddjD8g2H6g+UmQ5e8wvxskY2vaLpdesuYgUk+zE5lFjJntbl6U8kQqsGgJZw5iOceJwrgGaDoQYSz2r0F4uT049AblCvOtT2RW/dZR4EmvwTPv/vRWFQd0BZ0Xpb1vYKZyKHO5Ps2AHTtE5wbgSrMJQDjETkM+AW7SsrxBWi9zOnNYQLgbHKmiyfVGltc5EX3WlwuqPjQLGGrgpGJbaBDbDuGFVxrxCTo4Wuthau6Jfd7qNpvUMjiA6sRoASXYla2+wYtUvWQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gKFQa2A321zE7NJ/Ka4/AqQ75vN06yxtGnHsH0CUf/M=; b=GycWyS6JmxspoX9NJN6aIjFQwHECyjoXcqJnOslY7skZUmPtHuYyFPvkqzxwRXB+FKEBgCDMgdxcaTBvyzzVxvgU9L/ELY8Gm77zNbC9SP6SFfxGMwH8YISL/GOr2g4iY75I5095tmvgidPZwppq/Ua52PwPIRAFbgur9i8crNvd7gUL80peGL9qnkQSBkfsN/rghXHYowqQMGti+zMaKUanGaBidKPZeQUvjPNHl0vnY87f84+svlcXUWoJM8xbhniVHx/9VbNBbNZSO+JF24hQF7SSVWWOm0Er4ebBEmpd734TuU/QIwYWfFhvO/wjvDRwy+F5VJgshu0fPabzvQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) by GV2PR10MB6453.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:150:c3::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9253.18; Mon, 27 Oct 2025 09:24:39 +0000 Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe]) by DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe%4]) with mapi id 15.20.9253.017; Mon, 27 Oct 2025 09:24:38 +0000 From: "'MOESSBAUER, Felix' via isar-users" To: "isar-users@googlegroups.com" , "Bouska, Zdenek" CC: "Steiger, Christoph" , "cedric.hombourger@siemens.com" , "Kiszka, Jan" Subject: Re: [PATCH v3 00/10] Add SBOM generation with debsbom Thread-Topic: [PATCH v3 00/10] Add SBOM generation with debsbom Thread-Index: AQHcQ2oQNyvOicM6EUGZpxerjoGlHLTRDLYAgAAHNICABJMPAIAAGTmA Date: Mon, 27 Oct 2025 09:24:37 +0000 Message-ID: References: <20251022153921.2494749-1-felix.moessbauer@siemens.com> <94f9f4ed78522343bcc4d999d84d3894f3086e31.camel@siemens.com> In-Reply-To: Accept-Language: de-DE, en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: user-agent: Evolution 3.56.2-5 x-ms-publictraffictype: Email x-ms-traffictypediagnostic: DU0PR10MB6828:EE_|GV2PR10MB6453:EE_ x-ms-office365-filtering-correlation-id: cf5d6d51-9a06-42d5-25aa-08de153aa6a2 x-ms-exchange-atpmessageproperties: SA x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|376014|1800799024|366016|38070700021; x-microsoft-antispam-message-info: =?utf-8?B?U1RNZXBRcWYzRXFQcUMxOGtlZDFMRFlEcDhpakx4SGxDV2xkWEdSeXpNS3Nu?= =?utf-8?B?WGI4N0lTL0hxQVBjeTlsNDN2QTEyRjBzSlRVTmdVOUtycCtBNTNSdmdZcER2?= =?utf-8?B?MWRkUjM2aFhTU1Z2RDhDYk1sL0hYMnBSUGxHMjlxSXN3MzU1RTh1U3crQklE?= =?utf-8?B?VXliN3RtSVM5QzdPYXIzaFhVSGNKRzFkZEppVUhHSGVqR0U3a3BET1pVMkRP?= =?utf-8?B?Z3pucW1hZ0Z4NlM5SGJPMGlYY25tTmZ2Q1NQYUdTYUJrbkp0aGFPaGFUYUFi?= =?utf-8?B?ZmxNUndMdDlMMlpnbzRjTXZaV3l6OFYwZW9kVnlqUjV6ZjAzaVAxcWl1T1Fa?= =?utf-8?B?OWp4Mm9UN2NMT21NNW9iZDVFc1drNWZpZS9uaTNnOTZhamFrcStEdm1qa29N?= =?utf-8?B?SmVFT1B1d1YzU0lMcVRncUVpNlRSMktqK29ENWdRR2tYQ0NQR3lMdFphVkxo?= =?utf-8?B?TnRBRjJOZDNvRHBlU0cvR0F5cDlQcEVoZjdxTmxHQjRqeExBdS9FdUFxYkUv?= =?utf-8?B?YTJNVHltTVR1RnRtU3Uwdk5uOWRkeEFMYUYvTklrd2M5TW02ejU5VUJOWXN1?= =?utf-8?B?alVkbXFkYlBTK3ltSTRFamF6U0MyeCtOYk9nZ0g2Z3Z2WlJLR3RwMmkzYUJL?= =?utf-8?B?YlhoU0dySlFXeDdjd29qbFppZ3czTUFxWkVoOGtqODErNEhtSXU5eG9OUWxr?= =?utf-8?B?OGNkeDR1RGNreUo5dlRXMHJtTjhQLzR3cHAvOW5FWDVkelE2ZnJKanlrUURs?= =?utf-8?B?WEszR2lXWXZyQXVkYUg4bm1KYWN4Y0k1V3lOZnN1cmZXT3cyUG02UmtreDNi?= =?utf-8?B?NWpXN0YxMWFFUzNycWF1dzlkQVB1bnRVZURsWU5xN0IrY3pyYmhiVm1ZeThB?= =?utf-8?B?WUlsNzBYajBSbFk5cHZjeWtoQ3BQQm9HSDRpSS9DVjRyVFhvc3ZJNVdjeTFN?= =?utf-8?B?RE1NOVByOHVGc2t0WWV5TmNnaFJhcS92V3M2MzM5bkMya3o0R2NaS3ZVcG9Z?= =?utf-8?B?azJUU1p4OWlEUjhycnNieVFKTVA1TWRvS2liUklQTEtHYWVOMXFLeWliYkNB?= =?utf-8?B?emt3VjZXeHhzTGxmS08yeHVsRmJxdHFFVHRCZERONTdrRUNTQ1BHOTB2SzY4?= =?utf-8?B?Vnlub014blppbHNJWElnNWpKMytvaDJsMUh2V1o1dzBwelJwMkxlME9tN0px?= =?utf-8?B?V2Evb0p0TVBPRTM4bG9EUWhNRzJhZE5RUDNjNncvZWNUNm1iNXZ0eDZsbnVl?= =?utf-8?B?bitZckplR3U5Y2dabXpXSFRNbDlpZXFxNW5PZCs4ak9TeUtBd21wVzRodlhu?= =?utf-8?B?dDdtTVNoQ28vUVlrMDlMdkMzZUx0aWdpUFJJUGtxdHpHWERmVkg3bjFqb3kx?= =?utf-8?B?aUNLRU81WVpjQTJTK2NpNTJpd1dTQ1BYTHNMellvMDlwSXdDUk1hSHlTMWd0?= =?utf-8?B?bmxGNG1Gdmt0MDcrbFZlQnlGdFBpQTNpV0lqZW8yYjZxSUtTeGFrK2lnWjh0?= =?utf-8?B?a2pwQldVdWRobW9lNVA2ank1YnBOWEpqdTNnZEhNcUxoVm5wZERTcEk1dEVJ?= =?utf-8?B?ajg0RFBrenlPTUgrNllOZUpKU1E1d0lNa3NjRmFXcXR2KzF3YUNhMUpqOHBu?= =?utf-8?B?eGpiRGFvWjFhV0k0NHA4M3VhMlRhV0VMc3pEWjM4YzBXQlBjRzVETzBxTUp0?= =?utf-8?B?d2dKRlQ3bm9YKzV5dUNlUVZjU240RDhGK21VLzA0YndWYnluUmFDL21oVkUw?= =?utf-8?B?NzVpZlBucWFCRGU2eHUzOU5Kb0JQYzFyWmwyN2REYkRURjFKVWdhQll1TVBR?= =?utf-8?B?dVEydzRpa0ZSbEE2UXdRZk9FSFp0Q3NWdExYZFBJUVVxUjRGSXFRNTYvSmxR?= =?utf-8?B?a1cwK29iMG5hYlFqMUtZd09CSnhLYXQ3V0JjeXRVbWl3ZzVuc2Z2SE16em5s?= =?utf-8?B?cVpGZ2ZHZnZkWjEyQm5NK1c3aXNTNXhWeHl2WUtuQjBSZk02aW1WNnZkMFpI?= =?utf-8?B?N1RyR0ZaUWZlckZPdTlrK3JubW9jL3RJOC9pQnp1RmVKUVZGVm1rdEtHS1JN?= =?utf-8?Q?YZL0je?= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(1800799024)(366016)(38070700021);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?utf-8?B?clJUMEUzMGhRdU1WNUhTMVBUd2tJVzV6bmIyUk8zaG9oKzlSd0pEc091SnZl?= =?utf-8?B?dU5vb2MvQWJpL0ZBTkcwS1V2Z1pHdWxTaWpSU3lJS2R2Vll5VTd3R3NUdkRI?= =?utf-8?B?eXFNMmZTZ0phT1QzamhQZ0c4V0JyVVY3K0xGTlRVa1NSY2FBZ2ZLbGlnZkFm?= =?utf-8?B?dExrOWNQU1B6Tmh5SU9pQXdYQ1FKWmtJT1BINyt2UEVxeXU5TTN2UGxucmt0?= =?utf-8?B?d3l6WnFwb0VMRWZBM0kvT05WQmUrZm5rck14bndNSjljUmhhQjREb09aZHBz?= =?utf-8?B?RktCRjVnM3lPTHBNSXR4VHpyZnQrY3VnOUQzR01LZ0prSkJ2cWNmWXhqdHJi?= =?utf-8?B?c0FETWNYdGRBUlJibTZ5bmx0NXFwb3pYcGpCMXU4S2FvbE9ZTVVJRUQrUHox?= =?utf-8?B?S3F6WTBzN3huNmdQV2F4ck5CaWxnbkdaTnp6WVF6VXpiWlpUakN0QnpLaXV3?= =?utf-8?B?cUw4ZHAyVTJuM2RaY1ZMbDBva0swbC92M2N2Y09Xc0M2MFZFUnhnNVYzNlk0?= =?utf-8?B?ZEEwc3dVWHFUUmdCekVFOEhGL3psekJSN0ZwUTRTR2lxQUdLcjB2dmdjRWQ2?= =?utf-8?B?ZW05N3VyeGMzSXZhOE40ak1vdnkzMlVhR0MrVDA0M204bVRNWk9sRWk1dDVS?= =?utf-8?B?TUFEMTJqRmVhUDU0QWRGeGg0dXJ1OFZsb2xLdk1DNytpNXY4VzhZWUJmbmNt?= =?utf-8?B?bUN4OGJ1M3hHcmNkWW5DcmJycmJ0cHFkSHV4b1g0Mi8zbFh6L0tnSGxxMmtB?= =?utf-8?B?SWFidjJKVVhCSVBTTkpjUmtnQjBIeUZGY3dFbmF0YmdQdXlJQngxMkJoMzFx?= =?utf-8?B?ZWhGUTNGMVN5TFhUQTF0TWNQQ0VTRlJpcmFpKytGRDRNWDJBMXdJOXlpa3dC?= =?utf-8?B?WkpqVVlzYnNPQmIyZUsvdEtCOURGQzZrZ04zb0w1TWlrdDB2UmREcGhZa0M1?= =?utf-8?B?aDV2THRZR3FMczgrYm1XaXdFYmtDektMNEZDRTNtQWltUUdTM0gybmk5bWlS?= =?utf-8?B?QzVRRExDZmlrcmx4WTRYdHU2VTlza3dTMWpHZlJVN0FoY3BrTEtKaWlUcUcv?= =?utf-8?B?eWpLcnpwZG5EMGE1NEVuVzI5TFpodWpJZXBnanJldFJKcFY2QXBNb1owRklp?= =?utf-8?B?WlFVeVYrU2JvdkVOQm5sUnBoUkJ2UnZyVXgveGVKZnRhb09ablFzMnhQbVZW?= =?utf-8?B?dnJvRFY4M1hlRzBuWUo1NnAxUDFwVjNaMlhKbnArZHRBWU9JSkFOWHI3dDBP?= =?utf-8?B?TXV5WlFsL2IydGN3aTFkUWdvaVRLMk1pSEpFMkJ3UHhLbHZjeHNIdXQrd29Z?= =?utf-8?B?Q3A1ZUF3c2RYNjRyZDBPYlV6RGNyVWlhRnR1SFJ1dmpBazJkR2JINkZqY25N?= =?utf-8?B?N0diN2ozeW1BcDZ3QUU5NzhrYkdpS09OdVdVUGd5MDEvOFFCK3JhTXRBcGhD?= =?utf-8?B?cmljZFB0U1IwMG91ZHNPeWMvd3o1WHBXR003TDYwWHowa2Q5M2JQTTJqaHFw?= =?utf-8?B?WWY2VXlwc2NTVGJmcjhnZzRBRFRFcU9QUW04YXdOM0h6eDltU2tqbXFaN1ha?= =?utf-8?B?QXNjem4xRFZMbDBSK0g5cThvd2lwSHJHWFNTZ3cvR1FNK2UzSVNZbmNKK1Z0?= =?utf-8?B?N05RMFc2WW9nTU9GL3NhMXdPVm8wSytsRTQ1SExaZkozVHBDZXNpRXhtcnJ0?= =?utf-8?B?bElDWkNWQ3dOVE9nNXl4VVFDNDJKZkxRNkRTcmkyc0VqMnFZQ1BBZldzYUc0?= =?utf-8?B?eUlpaklIdW9uTjNqd1ZkNGZ6WnlRTmVJaHZqQmJETCs1K0dnNytmV0xWTFRo?= =?utf-8?B?ZXB2ck5IZFJWSWxHZU1OV25GbFJVTHJIWTVqN1VlVCt1UDRxVmtrSUFSc0dF?= =?utf-8?B?eXdOVmJDT3Q0ZDZGMUFqYXlIMm1SYjlyamFoTWxSTEpOdlhGSmJVV1N1YXBR?= =?utf-8?B?UUFzWmMybUpIRWlaWllZc3gwYk9NVmZUbHlIYzhPbW9BcmVTb2JxM2IwTHNj?= =?utf-8?B?RnJjS3VvOTl2WncvZ1ZhUVNBaTBsUk9XT2JiZUdGVjhOeDcwNEdhWVVuKzVW?= =?utf-8?B?bmZZRUZHYlo2L3gydmxEeTRESzZKdVZkalN5eEFlVmJqYy9ndlpuWUoyODVv?= =?utf-8?B?K3VWdlpxalRHVGYzY05VWmhhWWxpUnIzNkdzQ1lrVmljRWkxYm53cHJ4eTZO?= =?utf-8?B?MUE9PQ==?= Content-Type: text/plain; charset="UTF-8" Content-ID: <07DBD7EE30794C4294DFD22587E81392@EURPRD10.PROD.OUTLOOK.COM> Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-Network-Message-Id: cf5d6d51-9a06-42d5-25aa-08de153aa6a2 X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Oct 2025 09:24:38.0726 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: 1n5cBMCr70x2DECnFJ/E9Ei1C8SQR3nFnxOZXkmS+wKJK5FTvukGRoLDTTaif8lBMgCgxqS1oSciq0Lv3Dcfhb+QLSord/suo+cc+IkGoGw= X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV2PR10MB6453 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=dKake0OW; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::6 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: "MOESSBAUER, Felix" Reply-To: "MOESSBAUER, Felix" Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: dF8xbuIUuiqf On Mon, 2025-10-27 at 07:54 +0000, Bou=C5=A1ka, Zden=C4=9Bk (FT D EU CZ PDS= 1 ICC 1) wrote: > > Yes, definitely. At least in my SPDX SBOM this is listed (need to > > create a CDX one). Are you sure your bash magic is right? >=20 > Grub is not in SBOMs even if I look for it by text search. >=20 > Reproduce: >=20 > $ cat trixie_amd64.yml > header: > version: 14 >=20 > build_system: isar >=20 > machine: qemuamd64 > distro: debian-trixie >=20 > target: mc:qemuamd64-trixie:isar-image-base >=20 > repos: > isar: > path: isar > layers: > meta: > meta-isar: >=20 >=20 Thanks for insisting on this. I found the bug. It was a simple glitch in the naming of the imager SBOM which apparently slipped in while refactoring. The following patch fixes it (will be fixed in the v4 as well): diff --git a/meta/classes/image-tools-extension.bbclass b/meta/classes/image-tools-extension.bbclass index bfdb8a35..95f003d0 100644 --- a/meta/classes/image-tools-extension.bbclass +++ b/meta/classes/image-tools-extension.bbclass @@ -93,7 +93,7 @@ generate_imager_sbom() { --bind $schroot_dir /mnt/rootfs \ --bind ${WORKDIR} /mnt/deploy-dir \ -- debsbom -vv generate ${SBOM_DEBSBOM_TYPE_ARGS} \ - --from-pkglist -r /mnt/rootfs -o /mnt/deploy-dir/'${PN}- ${DISTRO}-${MACHINE}-imager' \ + --from-pkglist -r /mnt/rootfs -o /mnt/deploy-dir/imager \ --distro-name '${SBOM_DISTRO_NAME}-Imager' --distro- supplier '${SBOM_DISTRO_SUPPLIER}' \ --distro-version '${SBOM_DISTRO_VERSION}' --distro-arch '${DISTRO_ARCH}' \ --base-distro-vendor '${SBOM_BASE_DISTRO_VENDOR}' \ >=20 >=20 > I still got these SHA256 warnings, same as with custom kernel: >=20 > $ debsbom download --outdir downloads --sources tmp/trixie_amd64_wic/buil= d/tmp/deploy/images/qemuamd64/isar-image-base-debian-trixie-qemuamd64.wic.c= dx.json > WARNING:debsbom.download.resolver:no sha256 digest for linux@6.12.48-1. L= ookup will be imprecise > WARNING:debsbom.download.resolver:no sha256 digest for linux-signed-amd64= @6.12.48+1. Lookup will be imprecise > WARNING:debsbom.download.resolver:no sha256 digest for openssl@3.5.1-1+de= b13u1. Lookup will be imprecise > downloading 232 files, 545 MiB (cached: 0, 0 KiB) >=20 > > Hi, this means that the package was not found in the apt-cache. Did you > > try this series with a fresh build-dir (sstate cache is ok)? > >=20 > Warnings with custom patched kernel are these. Now I made sure, that I de= leted build dir: > WARNING:debsbom.download.resolver:no sha256 digest for linux-mainline@6.1= 7.2+r0. Lookup will be imprecise > WARNING:debsbom.commands.download:not found upstream: linux-mainline@6.17= .2+r0 <- this is expected=20 > WARNING:debsbom.download.resolver:no sha256 digest for openssl@3.5.1-1+de= b13u1. Lookup will be imprecise All these warnings are from built-using (except maybe for linux-mainline@6.17.2+r0). We discussed the topic upstream with the reproducible builds people [1] and finally came to the conclusion, that a name+version tuple is sufficient to identify a package (at least for the content of the package, the signature still needs clarification). By that, we will downgrade that warning to a info message (and add some explantaion to the documentation) [2]. [1] https://github.com/siemens/debsbom/pull/112 [2] https://lists.debian.org/debian-devel/2025/10/msg00236.html Best regards, Felix >=20 > Zdenek Bouska >=20 > --=20 > Siemens, s.r.o > Foundational Technologies --=20 Siemens AG Linux Expert Center Friedrich-Ludwig-Bauer-Str. 3 85748 Garching, Germany --=20 You received this message because you are subscribed to the Google Groups "= isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/= bc0005f268b05309fb135f037c010d316f1ad08d.camel%40siemens.com.