diff options
author | Petr Štetiar <ynezz@true.cz> | 2023-10-24 08:27:13 +0000 |
---|---|---|
committer | Petr Štetiar <ynezz@true.cz> | 2023-11-02 14:44:47 +0000 |
commit | 21e5db97c410f4008c8fe8515fb79a7cde368dbf (patch) | |
tree | 9b913ed60059392917ef2f5221b8eec13c482e89 /package/Makefile | |
parent | 4ef8899c7ab6ac9c69f7cc7138c3fc8a3fec777b (diff) | |
download | upstream-21e5db97c410f4008c8fe8515fb79a7cde368dbf.tar.gz upstream-21e5db97c410f4008c8fe8515fb79a7cde368dbf.tar.bz2 upstream-21e5db97c410f4008c8fe8515fb79a7cde368dbf.zip |
build: add CycloneDX SBOM JSON support
CycloneDX is an open source standard developed by the OWASP foundation.
It supports a wide range of development ecosystems, a comprehensive set
of use cases, and focuses on automation, ease of adoption, and
progressive enhancement of SBOMs (Software Bill Of Materials) throughout
build pipelines.
So lets add support for CycloneDX SBOM for packages and images
manifests.
Signed-off-by: Petr Štetiar <ynezz@true.cz>
(cherry picked from commit d604a07225c5c82b942cd3374cc113ad676a2519)
Diffstat (limited to 'package/Makefile')
-rw-r--r-- | package/Makefile | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/package/Makefile b/package/Makefile index 4b8df7f484..8e72d4ec72 100644 --- a/package/Makefile +++ b/package/Makefile @@ -106,6 +106,14 @@ ifdef CONFIG_SIGNED_PACKAGES $(STAGING_DIR_HOST)/bin/usign -S -m Packages -s $(BUILD_KEY); \ ); done endif +ifdef CONFIG_JSON_CYCLONEDX_SBOM + @echo Creating CycloneDX package SBOMs... + @for d in $(PACKAGE_SUBDIRS); do ( \ + [ -d $$d ] && \ + cd $$d || continue; \ + $(SCRIPT_DIR)/package-metadata.pl pkgcyclonedxsbom Packages.manifest > Packages.bom.cdx.json || true; \ + ); done +endif $(curdir)/flags-install:= -j1 |