Re: [OE-core] Adding more information to the SBOM

2022-09-14 Thread Joshua Watt
On Wed, Sep 14, 2022 at 12:10 PM Alberto Pianon wrote: > > Hi Joshua, > > nice to meet you! > > I'm new to this list, and I've always approached Yocto just from the > "IP compliance side", so I may miss important pieces of information. > That > is why Marta encouraged me and is helping me to ask

Re: [OE-core] Adding more information to the SBOM

2022-09-14 Thread Alberto Pianon
Hi Joshua, nice to meet you! I'm new to this list, and I've always approached Yocto just from the "IP compliance side", so I may miss important pieces of information. That is why Marta encouraged me and is helping me to ask community feedback. Il 2022-09-14 16:56 Joshua Watt ha scritto: On

Re: [OE-core] Adding more information to the SBOM

2022-09-14 Thread Joshua Watt
On Wed, Sep 14, 2022 at 9:16 AM Marta Rybczynska wrote: > > Dear all, > (cross-posting to oe-core and *-architecture) > In the last months, we have worked in Oniro on using the create-spdx > class for both IP compliance and security. > > During this work, Alberto Pianon has found that some

[OE-core] Adding more information to the SBOM

2022-09-14 Thread Marta Rybczynska
Dear all, (cross-posting to oe-core and *-architecture) In the last months, we have worked in Oniro on using the create-spdx class for both IP compliance and security. During this work, Alberto Pianon has found that some information is missing from the SBOM and it does not contain enough for