On Tue, 2026-09-29 at 08:16 +0200, Yoann Congal wrote:
> On Mon Sep 28, 2026 at 9:03 PM CEST, Daniel Turull via lists.openembedded.org 
> wrote:
> > From: Daniel Turull <[email protected]>
> >
> > We have a requirements to include release time of open source components
> > in the SBOM. There is a field specific for that in spdx 3 spec.
> >
> > https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/
> >
> > This can also be used to evaluate how old are some of the core
> > components and decide if they need replacement.
> >
> > The previous 2 versions did not have cover letter.
> >
> > Tested with oe-selftest -r spdx
> >
> > Daniel Turull (3):
> >   classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash
> >   create-spdx-3.0: record component release date in SPDX output
> >   scripts/contrib: add spdx-release-date-report.py
> >
> >  meta/classes-global/base.bbclass            |   4 +
> >  meta/classes/create-spdx-3.0.bbclass        |   2 +-
> >  meta/lib/oe/spdx30_tasks.py                 |  19 ++
> >  meta/lib/oeqa/selftest/cases/spdx.py        |  39 ++++
> >  scripts/contrib/spdx-release-date-report.py | 193 ++++++++++++++++++++
> >  5 files changed, 256 insertions(+), 1 deletion(-)
> >  create mode 100755 scripts/contrib/spdx-release-date-report.py
>
> Hello,
>
> Note: while this is not a fix, this looks related to
> https://bugzilla.yoctoproject.org/show_bug.cgi?id=15530
>
> Thanks!

Thanks for the pointer Yoann. I'll take a look if I can do something with the
ticket once I have the current series right.
Definitely the ticket is going in that direction that I was thinking.

Daniel

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246844): 
https://lists.openembedded.org/g/openembedded-core/message/246844
Mute This Topic: https://lists.openembedded.org/mt/121478114/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to