Re: [ptxdist] SBOM support

2024-03-08 Thread Simon Falsig
> From: Michael Olbrich > Sent: Monday, March 4, 2024 17:09 > Hi, > > On Mon, Feb 19, 2024 at 04:54:16PM +, Simon Falsig wrote: > > > I'd be happy to get a bit of initial feedback on the approach. I'll > > > have a look at putting up some initial patches in the coming days too. > > > > > >

Re: [ptxdist] SBOM support

2024-03-04 Thread Michael Olbrich
Hi, On Mon, Feb 19, 2024 at 04:54:16PM +, Simon Falsig wrote: > > I'd be happy to get a bit of initial feedback on the approach. I'll have a > > look at putting up some initial patches in the coming days too. > > > > Thanks in advance and best regards, > > Sorry for the silence around this,

Re: [ptxdist] SBOM support

2024-02-29 Thread Simon Falsig
> Hi, > > > I'd be happy to get a bit of initial feedback on the approach. I'll > > have a look at putting up some initial patches in the coming days too. > > > > Thanks in advance and best regards, > > Sorry for the silence around this, but I've been busy with other things in > the last months.

Re: [ptxdist] SBOM support

2024-02-19 Thread Simon Falsig
Hi, > I'd be happy to get a bit of initial feedback on the approach. I'll have a > look at putting up some initial patches in the coming days too. > > Thanks in advance and best regards, Sorry for the silence around this, but I've been busy with other things in the last months. Finally managed

Re: [ptxdist] SBOM support

2023-09-13 Thread Simon Falsig
Hi Gavin, Michael, > From: Gavin Schenk > Sent: Monday, September 11, 2023 15:11 > Hi, > > > On Thu, Sep 07, 2023 at 03:03:47PM +, Simon Falsig wrote: > >> I saw a post from 2021 to the mailing list on generating SBOMs from > ptxdist. > >> Has there been any further work on this? > > > >

Re: [ptxdist] SBOM support

2023-09-13 Thread Simon Falsig
Hi Michael, > From: Michael Olbrich > Sent: Friday, September 8, 2023 20:39 > > Hi, > > On Fri, Sep 08, 2023 at 09:05:26AM +, Simon Falsig wrote: > > Thanks for your reply! I've never used Buildroot, so really good with > > some hints as to how others solve this. > > > > >>My

Re: [ptxdist] SBOM support

2023-09-11 Thread Christian Melki
Shameless plug here. We (t2data) have been developing devsecops tools for quite some time. MAIA, our internally developed tool is capable of a lot of things. Among them is various classifications of software with licenses, CPE, CVE, CWE etc. Including availability of new versions etc. Built in is

Re: [ptxdist] SBOM support

2023-09-11 Thread Gavin Schenk
Hi, > On Thu, Sep 07, 2023 at 03:03:47PM +, Simon Falsig wrote: >> I saw a post from 2021 to the mailing list on generating SBOMs from ptxdist. >> Has there been any further work on this? > > I've not worked on this and I'm not aware of any other efforts in this > direction. > >> We've been

Re: [ptxdist] SBOM support

2023-09-08 Thread Michael Olbrich
Hi, On Fri, Sep 08, 2023 at 09:05:26AM +, Simon Falsig wrote: > Thanks for your reply! I've never used Buildroot, so really good with some > hints as to how > others solve this. > > >>My suggestion would be to add a _CPE variable to each package (built > >> from > >>whatever other

Re: [ptxdist] SBOM support

2023-09-08 Thread Michael Olbrich
Hi, On Thu, Sep 07, 2023 at 03:03:47PM +, Simon Falsig wrote: > I saw a post from 2021 to the mailing list on generating SBOMs from ptxdist. > Has there been any further work on this? I've not worked on this and I'm not aware of any other efforts in this direction. > We've been looking at

Re: [ptxdist] SBOM support

2023-09-08 Thread Simon Falsig
Hi Alex, Thanks for your reply! I've never used Buildroot, so really good with some hints as to how others solve this. >>My suggestion would be to add a _CPE variable to each package (built from >>whatever other variables make sense, typically _VERSION). I managed to >> add this >>

Re: [ptxdist] SBOM support

2023-09-07 Thread Alexander Dahl
Hello Simon, Am Thu, Sep 07, 2023 at 03:03:47PM + schrieb Simon Falsig: > Hi, > > I saw a post from 2021 to the mailing list on generating SBOMs from ptxdist. > Has there been any further work on this? > > We've been looking at implementing this internally - plan would be to generate > the

[ptxdist] SBOM support

2023-09-07 Thread Simon Falsig
Hi, I saw a post from 2021 to the mailing list on generating SBOMs from ptxdist. Has there been any further work on this? We've been looking at implementing this internally - plan would be to generate the SBOM in CycloneDX format, and consume it with Dependency-Track