pnoltes commented on PR #845:
URL: https://github.com/apache/celix/pull/845#issuecomment-5969804533

   I think it would be good to move towards a conclusion.
   
   My proposal is that we move ahead with Conan-based SBOM generation and, in 
follow-up PRs, introduce a vulnerability scan report that can be linked from 
the top-level README.
   
   I also think that the **Conan lockfile used for SBOM generation should not 
be considered set in stone**. If we do not like this approach, or notice that 
it creates too much maintenance burden, we can reconsider it and optionally 
move to an Ubuntu LTS-based setup instead, maybe using Trivy.
   
   For building and SBOM generation, it is useful to have a reproducible 
reference dependency set. For detecting potential upstream security issues, 
however, it would also be useful to regularly test against updated 
dependencies. Maybe we can add a CI workflow that periodically updates the 
reference lockfile, for example once a week?
   
   Seeing this discussion, I also think it would be good to rename the lockfile 
again. Sorry for asking for another rename, @mcc0nnell , but I think a good 
name can help convey its intended use.
   
   Given what we want to achieve, I think it would be better to explicitly 
state through the name that this lockfile is used for a reference build, and 
avoid terms such as "safe" or "security". Maybe we could rename it to 
`conan/reference-build.lock`?
   
   In addition, my proposal would be to update our security model in 
`SECURITY.md`, next to the already added `sbom.md`, to make the purpose and 
limitations of this Conan build explicit.
   
   The Conan dependencies used in Celix CI is primarily a reference/test 
configuration used to build and test Celix. The generated SBOM and 
vulnerability reports should be considered informational: Downstream users 
remain responsible for selecting and maintaining the dependency versions 
appropriate for their products.
   
   I would be willing to update `SECURITY.md` after this PR, or we can include 
that update in this PR.
   
   First, I think we need to align on the next step.
   
   @PengZheng , please let me know if you agree with introducing Conan-based 
SBOM generation for now. If not, that's also fine, and we can look for 
alternatives instead.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to