From: Daniel Turull <[email protected]> We have a requirements to include release time of open source components in the SBOM. There is a field specific for that in spdx 3 spec.
https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/ This can also be used to evaluate how old are some of the core components and decide if they need replacement. The previous 2 versions did not have cover letter. In v4 I kept the simpler logic to just check for the epoch date, even if we have multiple sources with different release dates. It was getting complicated and adding more code for git and tarfiles. I can do a follow up patch after this simpler version gets in, so we can fine tune it. Tested with oe-selftest -r spdx Daniel Turull (3): classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash create-spdx-3.0: record component release date in SPDX output scripts/contrib: add spdx-release-date-report.py meta/classes-global/base.bbclass | 4 + meta/lib/oe/spdx30_tasks.py | 22 +++ meta/lib/oeqa/selftest/cases/spdx.py | 41 +++++ scripts/contrib/spdx-release-date-report.py | 191 ++++++++++++++++++++ 4 files changed, 258 insertions(+) create mode 100755 scripts/contrib/spdx-release-date-report.py
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247084): https://lists.openembedded.org/g/openembedded-core/message/247084 Mute This Topic: https://lists.openembedded.org/mt/121543058/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
