pnoltes commented on code in PR #845:
URL: https://github.com/apache/celix/pull/845#discussion_r3928184175
##########
.github/workflows/conan_create.yml:
##########
@@ -67,6 +67,17 @@ jobs:
CXX: ${{ matrix.compiler[1] }}
run: |
conan create . -c tools.cmake.cmaketoolchain:generator=Ninja -b
missing -o celix/*:build_all=True -o celix/*:enable_ccache=True -pr:b default
-pr:h default -s:h build_type=${{ matrix.type }} -o celix/*:celix_cxx17=True -o
celix/*:celix_install_deprecated_api=True -o mosquitto/*:broker=True -o
*:shared=True
+ - name: Generate CycloneDX SBOM
+ if: matrix.compiler[0] == 'gcc'
+ run: |
+ conan install . -o celix/*:build_all=True --deployer=cyclone_1.6
--deployer-folder=sbom -b missing -o *:shared=True
+ - name: Upload CycloneDX SBOM
+ if: matrix.compiler[0] == 'gcc'
+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
# v4.6.2
Review Comment:
> Both SBOM and lockfile are associated with a specific set of
dependencies/options, and our users have freedom to change them at their will.
IMHO, providing them a safe defaults should be enough for now.
To ensure we are the same page, do you mean that
a) we should not configure a lock file in our source control
or
b) we can provide a lock file and sbom, but we should communicate that this
is a safe defaults, and users have to freedom to change the dependency versions
when needed.
I think I prefer option b, but then also document this more clearly (lock
file exists for safe defaults, and help in reproducible builds during
development)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]