From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Wed, 03 Dec 2025 14:32:27 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-yx1-f57.google.com (mail-yx1-f57.google.com [74.125.224.57]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 5B3DWQYr025868 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Wed, 3 Dec 2025 14:32:27 +0100 Received: by mail-yx1-f57.google.com with SMTP id 956f58d0204a3-63fac94e787sf7609393d50.1 for ; Wed, 03 Dec 2025 05:32:27 -0800 (PST) ARC-Seal: i=3; a=rsa-sha256; t=1764768741; cv=pass; d=google.com; s=arc-20240605; b=dflLqpcVHcA964bLJzGgF61Fu1ascPbhaa7jEjb5DkHEr1S0Gh65799crvSdPBjYW0 4JuLtlCkgz6t3wHS/YCS1B7MhuKiH1Eu6keZsHCsLIG7oiYyfrXLfP8ZPnXqV5O3NZEI xmmFHJ0JEfCqVHfcgonH92LegKKeyWlmkL5k7B7dO0IjWOEjpn0lJNmynwfCjG2LmuzP LjIjLzo4sjEMXd9ECsfmBKRjAzCcBzc/aodOkTOQZn6j/Ivjgz0rnHL457aYIU1Jm3V1 ziy++PVv2OShJMdV+8lRAm0TaZYzwtCKv8RnlmcYyBoq6ZHPlM7LqKPYWuxqJGkDIL61 tsrw== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version:content-id :user-agent:content-language:accept-language:in-reply-to:references :message-id:date:thread-index:thread-topic:subject:cc:to:from :dkim-signature; bh=ZxDBm4NJf/jjf1FjJzLXgTEeRm5J5evX1oyP6rHilIw=; fh=fOnsuS9f8+cX67PJ91wRNO6XccaxjhlAhDPKF7NJBJw=; b=PHkMPlVzTjj+5OFJk4163WPND4IHUrv5/y+aIsCuJNyxUNON99ak96lAGdQeJzB9tF 6euVhLN5QiykOI8iwx8mrxZDPUAps99AGp3PmKLV5edJ5e6mKzKe4twDPMHVV4NqO23Z KgF7Oef6xGdjUTvNR3xMDMCmTn3eZrg8GZNryHRcDe4S+4/4/aV13PTRZ5q0AqohS5mo hqmPJ0oJeVF53imaHZVW3KzsGZSofPc7uk9Ml1V+3TRWomo/JEZxENsHPb0oAE/bj8tX pOWrJgHVwrsB1aUzIT0LGqMwtMwqxG+W12DF/SBJ8ARAWzvn4u07mc6zmEWKdBWUEYC2 nZcA==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=ukI8rOYb; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c200::1 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1764768741; x=1765373541; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-id:user-agent:content-language:accept-language:in-reply-to :references:message-id:date:thread-index:thread-topic:subject:cc:to :from:from:to:cc:subject:date:message-id:reply-to; bh=ZxDBm4NJf/jjf1FjJzLXgTEeRm5J5evX1oyP6rHilIw=; b=fxc8TIVKkGLvSpBuzE/+qs+uhca5Dqg7CecEk1g5SoQ1leOVU7I4tIDFFyi8iU9SRo AC46lJtTcsDwnEACvEZRg7A/OgkGKcxxVkFoQ4QndOqgNIMlc2g9RdL9rqNGSksxyvBp UKy8SAzJ5nflVXirnZKrcMJe1dWi+tSs6spsCA3KUgl+wrO43O0f3rMTptRU+2dw80eX Rf27ny+awbeGPbqZCSTGMSwjsVbb7mQSyX+kJu5lCAAZW02RBt+7R4Yy8jRxBCeTMW1y 5anZP2lypDaVAPGM43kh113g6AB0g78EGU+Zzk9dQkt9hTrbH5YVrTgzcl4nF0UsFPsS 8cew== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764768741; x=1765373541; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-id:user-agent:content-language:accept-language:in-reply-to :references:message-id:date:thread-index:thread-topic:subject:cc:to :from:x-beenthere:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=ZxDBm4NJf/jjf1FjJzLXgTEeRm5J5evX1oyP6rHilIw=; b=DnWfnBGbPRSxpNU7Y4j9VeT1cJ9Yoy1Fg0oGgmB9D9J6pflBHAXC4nkQf4L9ZFlBxd XIjUti7wzlPJdM44fR1TflquqpqVUA1IITCR8/ebxmdPgKL7oysJ/c5sGEltxNmusj0R jJetmvdiU5COUcG0VtFrX++K/Pure8UnlyCyZBzxWyYKqTuzs+d83KPPJdFh+JaHnd30 J2V0ze4t7cmi7y2W7MtGb9eD9KPC99nf0Z3tC9TcrISG3kUTuSJS59eNNA2GHGWNoHsh f88t5kK9CXslQawT5HEEtHk/hRG41QzrxHRnir45/cnj14zrFE63PwprYf2ILHy5fuCU SwcA== X-Forwarded-Encrypted: i=3; AJvYcCUnAuY71oYTgMFipsQ20Mi8UUQLXTTTGrUhIVlodLEogJB73x+dmW8dAiWw0bAj0EkWSQRn@ilbers.de X-Gm-Message-State: AOJu0Ywg+qZvrJGwI9Bgkolf3aQezw54YEW2CF1dyyFUlUmuH235e2R/ Iy8z8o+7Y/wkKPTCFROOJPFTGcrB00jTBjcU8pRz5oKx6tlODnYIs6a+ X-Google-Smtp-Source: AGHT+IGu9K8KmgRs1JtLrXRXYsSFuz1XmM677EeGWj4ET5zgFT2f2OoVGNwGV/cQkj/TGam4Zsrr2A== X-Received: by 2002:a05:690e:1289:b0:63f:bab4:fde6 with SMTP id 956f58d0204a3-64436f6d8dbmr1849904d50.13.1764768740582; Wed, 03 Dec 2025 05:32:20 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="Ae8XA+Yvau+gCw9hP5fLNgMkihqKsHh+yKtQdoPCMpZcYAxuag==" Received: by 2002:a53:bf8d:0:b0:63e:1ef8:c7d with SMTP id 956f58d0204a3-64339334f1fls4572609d50.0.-pod-prod-01-us; Wed, 03 Dec 2025 05:32:19 -0800 (PST) X-Received: by 2002:a05:690e:134b:b0:640:cae6:6016 with SMTP id 956f58d0204a3-64436fab968mr1735137d50.20.1764768739064; Wed, 03 Dec 2025 05:32:19 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1764768739; cv=pass; d=google.com; s=arc-20240605; b=RDrVy7rDbHXApnOJkj8LZUXj4fJiB3QLopc2lR4ROMbLLYaAOSDBea6f4BGY/coiYB hwhPe27s2saV6mkQf16kT0bgGHB2GGzcUKcdeOl3tkhTde+5X7P4iWbquxC4oTZWEgAK ifXlk3aNQvXvItpzNJPt8Qbo4PgHDVKVDP1tAW3e4+vmHyCgvpuWm5elwhT6i9VHbWCx dfpYQdegopABU/23Vgtl/h1XqGCzJoqQEXdJ0vSXj7GlWo8vU2WRLm/Gxd0aPOW2C/2Q 1wINf6kQGz+P6UiJDYA0z3wT2gbrU97DcTuSzRVzxiDG2bFsTyzZ/tPhKb2zK6FgqK/7 Noow== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:content-id:user-agent :content-language:accept-language:in-reply-to:references:message-id :date:thread-index:thread-topic:subject:cc:to:from:dkim-signature; bh=ZawVj1sLiH/1V+mRfH3M8aVu+j3yBWv4SZcyq8giILw=; fh=yoz7w3bpmnzCjkjVRqfZHO2Kr2x2BqIKlUBPlAxdGYQ=; b=QqUy6rmK6P4nle88m8Dq3HvjV5IkiJsi0TwiNWtl182wkypHkw+qZpTCHYzRIPBzbt 9jiONDoG+QeBYo/ax24lCNod0VUFsXb9iFVH7UcKAjvAS1sRrHxh29L2dKBn24QRfxoD CqetWMskvfcvwVZq+OMxJzKsDyL414dKC9bx8AhZDdIf9kZywzfy5kA9CwFGDobRN2tn VoRXdnWAWrHi8b/mmy+HJJOdzL4CGpdwYO4b5BoJbAI6E9hpR8mBGrC7fSLmLEIgeSR6 yHi0pyqf9+5zyimLM2Kmhtw5RTUj8WENM55iTog1/I8MfPilXL3yRFen3lslfOv9ashB 3E6w==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=ukI8rOYb; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c200::1 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from DB3PR0202CU003.outbound.protection.outlook.com (mail-northeuropeazlp170100001.outbound.protection.outlook.com. [2a01:111:f403:c200::1]) by gmr-mx.google.com with ESMTPS id 00721157ae682-78ad0d82e0csi6286427b3.2.2025.12.03.05.32.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 03 Dec 2025 05:32:19 -0800 (PST) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c200::1 as permitted sender) client-ip=2a01:111:f403:c200::1; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=n2/2Rv0wUCITXqy4dxAlgWm8v7Hd8YMqe1IDR+d/cEfzpMb0IosyixFZaFg5nYu5iSHQpvt92QckhiJcX1dUJ0hDhWazloddJxUEvsJH6bCV+Vzkhyd07KLdyXNzVtEDeCKzo8ZmHPQ6RUkfGLwTa/6gXIvXUN4epBS2O9zl8MiZ5HjTYAu04TBTGXOLyu6LaGWzSIT62nGYM+Y73jJq0KSohY1/UUFRfOOHA6p3IidwVjS4xT4SknAVPXJrNIQsTJncCW85G5iTmXXfdj0dlJvueLaF9x3JNmIXUl+LKehe/jeUE3lgC6gGSBJlp5Our9OYbVFrcI5lLmelQmIY3A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ZawVj1sLiH/1V+mRfH3M8aVu+j3yBWv4SZcyq8giILw=; b=s61yhrte4xrrw6M0LXlJ/NjSaCQq0CBGmUdkUqfWO17rVx3AgA0J7J0CpI83ma9InFA5IoUSNLz/DJCJ6th4g/UrcpyY3Qmno/CsVgAbiF403aWdKDnSv160omaJ2CNGU6tjKChOghbe97rO//3xrqfVW6uHTXKWcCIISkdg7WBdLxvL7GkWyBThetrMZPc7DIVFk1GMUnbJv1g5Qom9dyzY+EyIQUN2A2j2fy/KqECu3MZ+CCeHZ8899v5iMPGb0EVTMW6IfnKZFsXaV72GIkqtXVMbRnR5faavFFotrNmuMSLSYszsa0MJUC98ZUrke8wEVCa2H455yeFq5iO84Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) by GVXPR10MB8105.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:150:113::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9366.17; Wed, 3 Dec 2025 13:32:16 +0000 Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe]) by DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::8198:b4e0:8d12:3dfe%4]) with mapi id 15.20.9388.003; Wed, 3 Dec 2025 13:32:16 +0000 From: "'MOESSBAUER, Felix' via isar-users" To: "isar-users@googlegroups.com" , "Kiszka, Jan" CC: "Steiger, Christoph" , "quirin.gylstorff@siemens.com" , "cedric.hombourger@siemens.com" Subject: Re: [PATCH v6 00/10] Add SBOM generation with debsbom Thread-Topic: [PATCH v6 00/10] Add SBOM generation with debsbom Thread-Index: AQHcYqCqMJoYNW/wIUSbsBb048Q1krUMgL6AgANseoA= Date: Wed, 3 Dec 2025 13:32:16 +0000 Message-ID: References: <20251201085813.1616095-1-felix.moessbauer@siemens.com> <20caede7-0708-4ed4-8aac-084bffaa6887@siemens.com> In-Reply-To: <20caede7-0708-4ed4-8aac-084bffaa6887@siemens.com> Accept-Language: de-DE, en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: user-agent: Evolution 3.56.2-7 x-ms-publictraffictype: Email x-ms-traffictypediagnostic: DU0PR10MB6828:EE_|GVXPR10MB8105:EE_ x-ms-office365-filtering-correlation-id: 976a2e01-adf2-423e-3dae-08de32706040 x-ms-exchange-atpmessageproperties: SA x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|376014|1800799024|366016|38070700021; x-microsoft-antispam-message-info: =?utf-8?B?UVdsSUtIckltWVJENE1YTUpWdkpDbEp6ZHVTNWgzNmlBdlpkTDA1aitKTzN1?= =?utf-8?B?ZjJuRTlnWXVJQTZqaklhVmppOHdvMnVodW9tYVczUXdGVVJWOWxPbFJKZ2tt?= =?utf-8?B?V29HQ2UydWIzNGlmM2NjQ01LZUxhc0lnenRUZUhrbEF6S0pGYWJzeEswek01?= =?utf-8?B?L1h0VDUwMExiaHpGanFKSjh1dWVvR214K2FELzN0VDQrR044NDg5VjhHbjZY?= =?utf-8?B?MlY5YmtjNEllL3lscWlwdmlvT09xRWVRaFN4V0ZCUGMwdDZ4UGJ4OHVlVnNT?= =?utf-8?B?YlloREY0S1ZsV1dkOFlWTWdXMDRQRG1xUk1CczV0akN3L3Nma1JiWlR4dHdO?= =?utf-8?B?QzJZUGQxMC9yWXJkNlpwdmFqUVRzcUQxUnBQajdnNXJFRVVYaGljNDZBYi9C?= =?utf-8?B?V2Z2QVNsMFJUTFFLblgvWHBlZmpMS0FyWWlObTUwOE9KaHd5cm1wS1I0d2hF?= =?utf-8?B?NDRSWWFaNzR1QU40L3d1NS9ZeXg4U0tKd0lyWjI5RXNSbElpekJqdE9OeGtt?= =?utf-8?B?TFVFb0J0aVVESVRjZTYwZ2M1Z2FRZk9weDJNN1lybEI3WUlJR2tEb3diOWk5?= =?utf-8?B?RW16VkRhbHBuV3BTdldtZytkNzU1Q20vV1RWK2M5Tk5XVXNrOTBTSnJNd0ps?= =?utf-8?B?bE9iVFIrTVpYZktiM1c5Skxqbis5cmFpZ2RieTlENHZYRjZjOE1xZTJkR3Jz?= =?utf-8?B?Wm9yYkUxQzJaM0xxb1hhdG03ZW0rckorUk81anIrRUdncENQSHZSZkFQalRQ?= =?utf-8?B?Zmw2dnFpRU9vb1BhdjFaOGNjd3ZqRTdHSTBXbGFFOE0zaXg1UFkwTDlZQUYr?= =?utf-8?B?cjZhSno1Ym84MkNqUEYwT2JvUmRqczBUaWdzd05PTFU1SnJlYTI2SHRLanBI?= =?utf-8?B?WjJkU1RsSVQxa2twcmtkZ2pvR3p0ZmFLRW04SFJscmdleHlkMlBiUzczaVlE?= =?utf-8?B?UUVPZmVkYTZoR3NjRjd5SkZHanhQc0w0bjJJWVdpQlhad2podW1XSHlSeUhy?= =?utf-8?B?cFpkQzNkZy9QTFFXYXhpUmovQld3RjhIcUtrS1Vmbm10YkhvWUlmNmRsVVBD?= =?utf-8?B?WjdjOEV4dkVPQmYvWjY1dllDOUowanNkbWRWdjM0WCtjVTlYck5qQlQ2eE02?= =?utf-8?B?NE16RXRHd3NkdUtLLy9wTkF6RVJ1aWFuMEFMckY5NVQreVVIcjlMZTQ5b0pn?= =?utf-8?B?Z2lsOUxQdGQrODExK1A5SHhoOEFybU1KZ2VacEVSVkNkUmxVSUZrMk9SN3pV?= =?utf-8?B?ci9VcHVnVWw3ZjkweHk3RTFSYmRyVUc0ZmtjRldwNURFc2M1dEFLWnZmV0xv?= =?utf-8?B?Zmo5VGhQeFdUQ2xueDlxcFJpSFZ1QkhqajdhOEFmUWZsWUNUcmQwNmV5Qkpr?= =?utf-8?B?Mk96Njl4RXdxOFM4MlhUT1NsbHZjdElaL1BwSDE5bUo2WVZhUjdIZ2g4Z29t?= =?utf-8?B?WjZFTlRvTXVqM2lWemIwL2VxNW84OEYyQlhocEFBR1NScUlYcjY4eHIrdzd5?= =?utf-8?B?am1VRXFYcmt3MmQwU3ZGMFc1TnFzUWszWHdxanh2RXVBbFpSNzRXeG5LNy90?= =?utf-8?B?VXE1UDdOdkhIVmp5alI5NEc0RndNN0xxSzNUY0ppdEJKUFQ0NFg2TUg4S1RL?= =?utf-8?B?cmlCa1NINmVOaVRIOEUxdTh0V0lBYkt6ZFFxYWs1NDRMakJRaXNKM28wY0VG?= =?utf-8?B?MkRGZXlSZ0pRRXl6V2VDLzVGMHJsQXFISWVoYjVVbEJpUEh4amc4Skt5ckVv?= =?utf-8?B?UnM4eEFpTEhnTjVxaEdHdkNKaUNPMWlZekdXZS9ERUNkK3k0SmpEeHZrbStp?= =?utf-8?B?bGR0ajNDU01mcks1Qy81OERGSHM1M1hOM1czUWQwVVpROEpmWk9KWkRhKzRv?= =?utf-8?B?dEVLbkZneGxNRTE3eG8yK25VWW5FbmhTTlJocEVRcW1uc0ZkdmpDMlUvWi9l?= =?utf-8?B?MTE3TXZ2NUUvUHRDSmxSclJQVysyTVNIT05GWjgwNW5MVm1XdGtnSUF4VDV0?= =?utf-8?B?SUVVQi9qNFJBPT0=?= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(1800799024)(366016)(38070700021);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?utf-8?B?djVML1VlOVMyV2VYWjZCcklodlRlU2o4Ni80QmVTdEFlM1ltUnRGRWN1RGJT?= =?utf-8?B?MDZOMU45QUNjUXU0NWlCQXVaZjJDTnhrZ2poNVo4TmtFWEs4YUlxRVB5d0dV?= =?utf-8?B?NUpaMjlBU25RMk1WUWlwZysvQ0xzM2F1YzNMdW4zT2ozNnNqZ0JQeGsyN3BQ?= =?utf-8?B?MmN3WUFXZ01KVnNybi9uL0NpVFg1RStDWUZ1Q0lFMlUySVNVbXNPMUE3UFZI?= =?utf-8?B?R3g5N21HZ1EycFgyQkd1ZDlmaVErT29sMlR3R0w4TTJLZVFQNlF2YUs1NzBU?= =?utf-8?B?SGVmRnEyZmtrRXdYNFBwQ3oxU3Zib2VrM2ZFcFZ1aFBWYndnajVYc045eDNO?= =?utf-8?B?ZXdmbzlxa2Y1WXZLQnNZVnNaaW5UVTZmTmRSdStwS09jQ2d2cXZ4WC9MM3l6?= =?utf-8?B?am02MkIxS084WkRkSURPRHZST05SejVBMk8rOXd0V1hmWklzSlF1a3h1S1lw?= =?utf-8?B?WlB5SjB3Y0s1d2d3RFZibGFsUmdGeDdVSldFWVlSdlMwK1R2ZjF1QlZyMlgx?= =?utf-8?B?UXoveUprUnNRU09xS3pnZW0xMTd4N0l6YU9kSFdRN3NtNG5ka0Y1c3VhbTlT?= =?utf-8?B?V0Y5TXl3V3FuNmZtVkROWVgvSkt1RGNCT0llV0d6dStDWVZkY3hHZDBoclVH?= =?utf-8?B?QnVQQlBXZHNNZkRmeGhWMFhwYkc3VXpmUnViR0Q5R1lZSUNaeE9VaGRoZXR6?= =?utf-8?B?UzkxWUZMaWxqcW1QV2wxamFNam5VcmJuVkFuVHlxRi9kai9yY04zV3p3NXU4?= =?utf-8?B?Z1BadFhpdzJHdlFiWkhFOXF5SCt0TWlXd1JjSlJtYnVIMjA5ekFlWXNsZk1Y?= =?utf-8?B?VHAySkZUNzBwUzhGYy8zSXFQd3plRGZKZnlJSXg4TWt4ZERMUEpWcS9VRDVk?= =?utf-8?B?Z3JIcmVrNFc0MXYwWFBnU2ZkRG1zM2Vnbk9WUG96WU5PUjVQU1phWklJVjVO?= =?utf-8?B?WjArbm5zVVRNditadHQ1RVFlU0ptcHdkaWllanJ2VlIrSXl2Y3RzZ0lvbUVs?= =?utf-8?B?Q1hOMnFucUNWMVk0NnJOekc4MktPOWg3YUxreXRtRnpVQXhBNlIzUTJKRWNu?= =?utf-8?B?ci9tNmlwNGFQVHJUUWRaN1RZV0VVWEdhU1J5aW5UU3ExVEJHQnliTFlGNzhl?= =?utf-8?B?VTBvamtwa2NlL3FiK2diZDFNZ3ZUZVRodi9VU1hNRzBXaGpqR3oxZldUNG54?= =?utf-8?B?WEptT3VIelg1NE9ndGtQZHl6NjJPR2R5dXZ2R1FicW93SDkxZjFRZ3NqY3pu?= =?utf-8?B?eFRPQ2theFhKU2locG5YdFZGZEIydVhFazVVRWZuK2s0bUR0dmM3amVWMTd2?= =?utf-8?B?MkFSbCt5bW1DaGdxT1V3UENBMEgrS3ZZMUpFVy92Z2tBRGlqV1haRTVzY2ps?= =?utf-8?B?Q1UvQXR0TlJiNjJaMlpBYkhORitFcDJ1MDRlLzl0MGJaa25lL08zSEpIMyt1?= =?utf-8?B?QXNMZVZPcnNPc01lamZXcTdqcEF3MEVLaFMzTFhJMEtFcDV1QUNFblV3Y28z?= =?utf-8?B?VWhBb2pGY2ZGYXZlRkU4VXV5ZGpjRVFXK0gxL2twRXZoS01NM3cwbEFoMWs5?= =?utf-8?B?blFlV0xEMVgxSjBBZ1RQOCtDUW5kbW9xeHc4Z20veHVaMG5laGhmbDFiMjVF?= =?utf-8?B?aFBTQmZzSldEY1VHcktkWnVjaGg0L3p1RWtjWkdsYmViUDYyUDN3OWFMYml6?= =?utf-8?B?eUlucEVuZ0pJYUFxdXVjRjZqOTU5bjJ5VlV1Y0ZnZTF3U013UU5JRlVhb3FS?= =?utf-8?B?RDExdGVrbjdvRk1tQ2pKNkZJajZDZ1lyT3R1OGxoYmkvMVFERGdCMmFKOWlu?= =?utf-8?B?eERHZ0xOQ0tybTRJM1laV2JuREJoeUI4Mll3ckV3UTEyaHhFRU02UVZvZ1l1?= =?utf-8?B?TzFneVVCN0lSUC8waDhaMG5TazRKeFkzaVdrOWl0TG9tL3R2eTdhRmtHTHI1?= =?utf-8?B?MG1wKzNkbnBBYVh0aW4zL0FlV1FiazNUZGlreEYzRi9KdHhjY0paNCtLZGNs?= =?utf-8?B?UkpJRmpFbTNXV25qdjRQcHdMb0JHS0ZCWDUzQjMxdy85dEhVeUxHQW5TTUJa?= =?utf-8?B?UVIwT1FhR3dGanY3Nnh3bzdrSnV3VnZERWdsWHZJeGE4b3VCVDBjMTE1WlFv?= =?utf-8?B?Um9DYU9FRW5GcHU2cTU4V2tiVTVkUlZFK0ZOY2tQVFZoTjQvQXpPU0pjbzVy?= =?utf-8?Q?27H9dOR81KyfSVljZ8ZhHvU=3D?= Content-Type: text/plain; charset="UTF-8" Content-ID: MIME-Version: 1.0 X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-Network-Message-Id: 976a2e01-adf2-423e-3dae-08de32706040 X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Dec 2025 13:32:16.5508 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: sWAcRQUKOfUsVHdCQ0YP2//yz2jOVKUlQbacvDrXm7Pb0v5BEOGYmc8+jGe6y+eCDARt+7w5fSFo+WU9v3z/4mNI3VsmFJnRn3DOct19fzs= X-MS-Exchange-Transport-CrossTenantHeadersStamped: GVXPR10MB8105 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=ukI8rOYb; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c200::1 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: "MOESSBAUER, Felix" Reply-To: "MOESSBAUER, Felix" Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: /MypqtHhCYSW On Mon, 2025-12-01 at 10:15 +0100, Jan Kiszka wrote: > On 01.12.25 09:58, Felix Moessbauer wrote: > > This patchset adds proper SBOM generation in the two standard formats > > SPDX and CycloneDX during the rootfs generation process. > > > > The generation is itself is handled by a SBOM generator `debsbom` [1] > > which is developed as an open source project at Siemens. It is still > > early in development, but it has enough features for what we require > > in isar. The required dependencies which are not yet available as > > Debian packages were minimally packaged directly in isar too. > > > > This is a followup of the previous RFC [2]. Since then the series has > > changed a lot. The SBOM generation was moved from a simple OE lib to > > `debsbom`. This also meant the introduction of a separate chroot was > > necessary. The SBOM generation process was also moved from the image > > step to the rootfs step, along with a lot of minor changes and > > improvements. > > > > [1] https://github.com/siemens/debsbom > > [2] https://groups.google.com/g/isar-users/c/8L-CF4BJY0I/m/p0N3o_zfAAAJ > > > > Changes since v5: > > > > - fix isar-image-ci on qemuamd64-bullseye (set IMAGER_BOM according to > > machine changes made in image file) > > - rebased onto next > > > > Changes since v4: > > > > - rebased onto next > > - fix race condition on creation of ${DEPLOY_DIR_SBOM} (aka ${DEPLOY_DIR_IMAGE}) > > > > Changes since v3: > > > > - fix issue on external bullseye initramfs (we now disable sbom generation > > on all unsupported distros rootfs instances) > > - update debsbom to v0.4.0 > > - rebased onto next > > > > Changes since v2: > > > > - fix issues when HOST_ARCH != DISTRO_ARCH on derived distributions > > - update debsbom to v0.3.0, which fixes the Origin: bug reported in v2 > > - generate SBOM for imager as well and create merged sbom of .wic image > > - resend imager manifest + wic manifest patches to reduce conflicts > > > > Note, that the patches p1-p5 are most important as they add basic SBOM > > support. The remaining patches address the imager + .wic bom part, > > which also can be merged later on. > > > > Changes since v1: > > > > - remove tarball > > - refactor packaging (auto-derive python dependencies) > > - only build missing packages (varies on bookworm, trixie, noble) > > - add ubuntu support > > - only generate sboms for supported distributions (bookworm/jammy and > > onwards) > > - update debsbom (includes bug fixes and more information for source > > packages) > > > > > > Christoph Steiger (3): > > meta: package python libraries for SBOM generation > > meta: package python3-debsbom > > meta: add SBOM generation with debsbom > > > > Felix Moessbauer (7): > > refactor: move get_rootfs_distro from sdk into rootfs > > override distro vendor in SBOM on Ubuntu > > add support to add imager dependencies to BOM > > wic: create uniform manifest describing all image components > > qemuamd64: add IMAGER_BOM entries > > imager: create SBOM of IMAGER_BOM packages > > wic: create uniform SBOM describing all image components > > > > doc/user_manual.md | 1 + > > meta-isar/conf/distro/ubuntu-common.inc | 2 + > > meta-isar/conf/machine/qemuamd64.conf | 1 + > > .../recipes-core/images/isar-image-ci.bb | 1 + > > meta/classes/image-tools-extension.bbclass | 29 +++++++++ > > meta/classes/image.bbclass | 7 ++ > > meta/classes/imagetypes_wic.bbclass | 30 +++++++++ > > meta/classes/initramfs.bbclass | 3 +- > > meta/classes/rootfs.bbclass | 23 ++++++- > > meta/classes/sbom.bbclass | 65 +++++++++++++++++++ > > New classes should go into the right category already, then rebasing is > easier for whoever has to do it in the light of > https://patchwork.isar-build.org/project/isar/list/?series=1780. Look at > the dracut series. Hi, according to my interpretation of the use-more-classes series and the dracut series, the sbom class is already correct. The sbom series also cleanly applies and works on top of the use-more-classes series. Felix > > Jan > > -- > Siemens AG, Foundational Technologies > Linux Expert Center -- Siemens AG Linux Expert Center Friedrich-Ludwig-Bauer-Str. 3 85748 Garching, Germany -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/c52a6c4481da1f6f3ca2a01b8e7948ef33b0bcc0.camel%40siemens.com.