While the revision D56474 introduces a framework allowing the generation of SBOM information when building the tree, it was missing the corresponding meta-data representing the software built and packaged during the build. This revision closes that gap, and aims at offering a balanced amount of SBOM artefacts corresponding to the build.
The granularity provided by the combination of D56474 and this revision attempts to:
- Provide one SBOM artefact per package entry in packages;
- Provide an SBOM for each library linked by a binary installed, when not already shipped as a package specifically,
- While ignoring libraries marked as internal.
I have tried to be as faithful as possible to the information I could find for each and every SBOM artefact generated, combining information obtained during the Alpha-Omega Beach Cleaning project, from Tuukka Pasanen while sponsored by the Sovereign Tech Fund, and with a final manual review.
Copyright information in particular was tricky, since many projects had multiple entries, while the SBOM definition file in pkgconf's format only expects one line; I usually stuck with the original holder, unless the project was marked with a major contribution or rewrite since.
Please do not hesitate to review, challenge, or discuss the information as appropriate.
Sponsored by: Alpha-Omega, FreeBSD Foundation, Sovereign Tech Fund