On Fri Oct 2, 2026 at 9:54 AM CEST, Daniel Turull via lists.openembedded.org 
wrote:
> From: Daniel Turull <[email protected]>
>
> We have a requirements to include release time of open source components
> in the SBOM. There is a field specific for that in spdx 3 spec.
>
> https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/
>
> This can also be used to evaluate how old are some of the core
> components and decide if they need replacement.
>
> The previous 2 versions did not have cover letter.
>
> In v4 I kept the simpler logic to just check for the epoch date, even if
> we have multiple sources with different release dates. It was getting
> complicated and adding more code for git and tarfiles. I can do a follow
> up patch after this simpler version gets in, so we can fine tune it.
>
> Tested with oe-selftest -r spdx
>
> Daniel Turull (3):
>   classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash
>   create-spdx-3.0: record component release date in SPDX output
>   scripts/contrib: add spdx-release-date-report.py
>
>  meta/classes-global/base.bbclass            |   4 +
>  meta/lib/oe/spdx30_tasks.py                 |  22 +++
>  meta/lib/oeqa/selftest/cases/spdx.py        |  41 +++++
>  scripts/contrib/spdx-release-date-report.py | 191 ++++++++++++++++++++
>  4 files changed, 258 insertions(+)
>  create mode 100755 scripts/contrib/spdx-release-date-report.py

Hi Daniel,

It looks like one of the added tests is failing here:

2026-10-03 15:26:28,760 - oe-selftest - INFO - 
spdx.SPDX30Check.test_release_date_source_date_epoch (subunit.RemotedTestCase)
2026-10-03 15:26:28,761 - oe-selftest - INFO -  ... FAIL
...
2026-10-03 15:26:28,761 - oe-selftest - INFO - 
testtools.testresult.real._StringException: Traceback (most recent call last):
  File 
"/srv/pokybuild/yocto-worker/oe-selftest-debian/build/layers/openembedded-core/meta/lib/oeqa/selftest/cases/spdx.py",
 line 473, in test_release_date_source_date_epoch
    self.assertEqual(pkg.releaseTime, expected)
  File "/usr/lib/python3.11/unittest/case.py", line 873, in assertEqual
    assertion_func(first, second, msg=msg)
  File "/usr/lib/python3.11/unittest/case.py", line 866, in _baseAssertEqual
    raise self.failureException(msg)
AssertionError: datetime.datetime(2023, 7, 18, 6, 55, 23, 
tzinfo=datetime.timezone.utc) != datetime.datetime(2011, 4, 5, 23, 0, 
tzinfo=datetime.timezone.utc)

https://autobuilder.yoctoproject.org/valkyrie/#/builders/35/builds/4997

Thanks,
Mathieu

-- 
Mathieu Dubois-Briand, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247170): 
https://lists.openembedded.org/g/openembedded-core/message/247170
Mute This Topic: https://lists.openembedded.org/mt/121543058/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to