pnoltes commented on PR #845: URL: https://github.com/apache/celix/pull/845#issuecomment-5969804533
I think it would be good to move towards a conclusion. My proposal is that we move ahead with Conan-based SBOM generation and, in follow-up PRs, introduce a vulnerability scan report that can be linked from the top-level README. I also think that the **Conan lockfile used for SBOM generation should not be considered set in stone**. If we do not like this approach, or notice that it creates too much maintenance burden, we can reconsider it and optionally move to an Ubuntu LTS-based setup instead, maybe using Trivy. For building and SBOM generation, it is useful to have a reproducible reference dependency set. For detecting potential upstream security issues, however, it would also be useful to regularly test against updated dependencies. Maybe we can add a CI workflow that periodically updates the reference lockfile, for example once a week? Seeing this discussion, I also think it would be good to rename the lockfile again. Sorry for asking for another rename, @mcc0nnell , but I think a good name can help convey its intended use. Given what we want to achieve, I think it would be better to explicitly state through the name that this lockfile is used for a reference build, and avoid terms such as "safe" or "security". Maybe we could rename it to `conan/reference-build.lock`? In addition, my proposal would be to update our security model in `SECURITY.md`, next to the already added `sbom.md`, to make the purpose and limitations of this Conan build explicit. The Conan dependencies used in Celix CI is primarily a reference/test configuration used to build and test Celix. The generated SBOM and vulnerability reports should be considered informational: Downstream users remain responsible for selecting and maintaining the dependency versions appropriate for their products. I would be willing to update `SECURITY.md` after this PR, or we can include that update in this PR. First, I think we need to align on the next step. @PengZheng , please let me know if you agree with introducing Conan-based SBOM generation for now. If not, that's also fine, and we can look for alternatives instead. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
