From: Daniel Turull <[email protected]>

We have a requirements to include release time of open source components
in the SBOM. There is a field specific for that in spdx 3 spec.

https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/

This can also be used to evaluate how old are some of the core
components and decide if they need replacement.

The previous 2 versions did not have cover letter.

In v4 I kept the simpler logic to just check for the epoch date, even if
we have multiple sources with different release dates. It was getting
complicated and adding more code for git and tarfiles. I can do a follow
up patch after this simpler version gets in, so we can fine tune it.

Tested with oe-selftest -r spdx

Daniel Turull (3):
  classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash
  create-spdx-3.0: record component release date in SPDX output
  scripts/contrib: add spdx-release-date-report.py

 meta/classes-global/base.bbclass            |   4 +
 meta/lib/oe/spdx30_tasks.py                 |  22 +++
 meta/lib/oeqa/selftest/cases/spdx.py        |  41 +++++
 scripts/contrib/spdx-release-date-report.py | 191 ++++++++++++++++++++
 4 files changed, 258 insertions(+)
 create mode 100755 scripts/contrib/spdx-release-date-report.py

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247084): 
https://lists.openembedded.org/g/openembedded-core/message/247084
Mute This Topic: https://lists.openembedded.org/mt/121543058/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to