pnoltes commented on code in PR #845:
URL: https://github.com/apache/celix/pull/845#discussion_r3928184175


##########
.github/workflows/conan_create.yml:
##########
@@ -67,6 +67,17 @@ jobs:
           CXX: ${{ matrix.compiler[1] }}
         run: |
           conan create . -c tools.cmake.cmaketoolchain:generator=Ninja -b 
missing -o celix/*:build_all=True  -o celix/*:enable_ccache=True -pr:b default 
-pr:h default -s:h build_type=${{ matrix.type }} -o celix/*:celix_cxx17=True -o 
celix/*:celix_install_deprecated_api=True -o mosquitto/*:broker=True -o 
*:shared=True
+      - name: Generate CycloneDX SBOM
+        if: matrix.compiler[0] == 'gcc'
+        run: |
+          conan install . -o celix/*:build_all=True --deployer=cyclone_1.6 
--deployer-folder=sbom -b missing -o *:shared=True
+      - name: Upload CycloneDX SBOM
+        if: matrix.compiler[0] == 'gcc'
+        uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 
# v4.6.2

Review Comment:
   > Both SBOM and lockfile are associated with a specific set of 
dependencies/options, and our users have freedom to change them at their will. 
IMHO, providing them a safe defaults should be enough for now.
   
   To ensure we are the same page, do you mean that 
   
   a) we should not configure a lock file in our source control
   
   or 
   
   b) we can provide a lock file and sbom, but we should communicate that this 
is a safe defaults, and users have to freedom to change the dependency versions 
when needed. 
   
   I think I prefer option b, but then also document this more clearly (lock 
file exists for safe defaults, and help in reproducible builds during 
development)



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to