On Tue, 2026-09-29 at 08:16 +0200, Yoann Congal wrote: > On Mon Sep 28, 2026 at 9:03 PM CEST, Daniel Turull via lists.openembedded.org > wrote: > > From: Daniel Turull <[email protected]> > > > > We have a requirements to include release time of open source components > > in the SBOM. There is a field specific for that in spdx 3 spec. > > > > https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/ > > > > This can also be used to evaluate how old are some of the core > > components and decide if they need replacement. > > > > The previous 2 versions did not have cover letter. > > > > Tested with oe-selftest -r spdx > > > > Daniel Turull (3): > > classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash > > create-spdx-3.0: record component release date in SPDX output > > scripts/contrib: add spdx-release-date-report.py > > > > meta/classes-global/base.bbclass | 4 + > > meta/classes/create-spdx-3.0.bbclass | 2 +- > > meta/lib/oe/spdx30_tasks.py | 19 ++ > > meta/lib/oeqa/selftest/cases/spdx.py | 39 ++++ > > scripts/contrib/spdx-release-date-report.py | 193 ++++++++++++++++++++ > > 5 files changed, 256 insertions(+), 1 deletion(-) > > create mode 100755 scripts/contrib/spdx-release-date-report.py > > Hello, > > Note: while this is not a fix, this looks related to > https://bugzilla.yoctoproject.org/show_bug.cgi?id=15530 > > Thanks!
Thanks for the pointer Yoann. I'll take a look if I can do something with the ticket once I have the current series right. Definitely the ticket is going in that direction that I was thinking. Daniel
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246844): https://lists.openembedded.org/g/openembedded-core/message/246844 Mute This Topic: https://lists.openembedded.org/mt/121478114/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
