PengZheng commented on code in PR #845:
URL: https://github.com/apache/celix/pull/845#discussion_r3877380915
##########
.github/workflows/conan_create.yml:
##########
@@ -67,6 +67,17 @@ jobs:
CXX: ${{ matrix.compiler[1] }}
run: |
conan create . -c tools.cmake.cmaketoolchain:generator=Ninja -b
missing -o celix/*:build_all=True -o celix/*:enable_ccache=True -pr:b default
-pr:h default -s:h build_type=${{ matrix.type }} -o celix/*:celix_cxx17=True -o
celix/*:celix_install_deprecated_api=True -o mosquitto/*:broker=True -o
*:shared=True
+ - name: Generate CycloneDX SBOM
Review Comment:
I'm not sure whether conan_create.yml is the right place to add SBOM
support, since a conan package is just a recipe to cook, not the final binary
package and SBOM only makes sense for binary package.
For example, I can use `--require-override` conan option when building Celix
to upgrade openssl to fix a security vulnerability without modifying either
Celix or the Celix conan reciple.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]