Page MenuHomeFreeBSD

SBOM: import SBOM meta-data
Needs ReviewPublic

Authored by khorben on Mon, Oct 5, 12:09 AM.

Details

Summary

While the revision D56474 introduces a framework allowing the generation of SBOM information when building the tree, it was missing the corresponding meta-data representing the software built and packaged during the build. This revision closes that gap, and aims at offering a balanced amount of SBOM artefacts corresponding to the build.

The granularity provided by the combination of D56474 and this revision attempts to:

  • Provide one SBOM artefact per package entry in packages;
  • Provide an SBOM for each library linked by a binary installed, when not already shipped as a package specifically,
  • While ignoring libraries marked as internal.

I have tried to be as faithful as possible to the information I could find for each and every SBOM artefact generated, combining information obtained during the Alpha-Omega Beach Cleaning project, from Tuukka Pasanen while sponsored by the Sovereign Tech Fund, and with a final manual review.

Copyright information in particular was tricky, since many projects had multiple entries, while the SBOM definition file in pkgconf's format only expects one line; I usually stuck with the original holder, unless the project was marked with a major contribution or rewrite since.

Please do not hesitate to review, challenge, or discuss the information as appropriate.

Sponsored by: Alpha-Omega, FreeBSD Foundation, Sovereign Tech Fund

Test Plan
$ make buildworld buildkernel packages
$ ls -1 /usr/obj/usr/src/amd64.amd64/share/sbom/*.pc | wc -l
227
$ ls -1 /usr/obj/usr/src/amd64.amd64/share/sbom/*.jsonld | wc -l
218
$ ls -1 /usr/obj/usr/src/amd64.amd64/share/sbom/*.spdx | wc -l
218

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped