SovereignCloudStack / issues

This repository is used for issues that are cross-repository or not bound to a specific repository.
https://github.com/orgs/SovereignCloudStack/projects/6
2 stars 1 forks source link

Extension of the OSISM SBOM by packages and checksums #150

Open berendt opened 2 years ago

berendt commented 2 years ago

As an SCS operator, I want to have a complete list of software (SBOM) (along with sources and versions) that gets pulled into my SCS deployment.

TODO:

NOT YET TODO:

Definition of Ready:

Definition of Done:

berendt commented 2 years ago

Sample for 3.2.0: https://github.com/osism/sbom/commit/a3d0820e6261250e648b3e18312da55017ced292

berendt commented 2 years ago

Moved to Blocked. The preparation for the airgap is still needed for the list of the individual packages.

garloff commented 2 years ago

Cryptographic checksums are there and sufficient (sha256 for each container/artifact). Should be mentioned in release notes.

berendt commented 2 years ago

Prepare SPDX files for several container images (ceph-ansible, kolla-ansible, osism-ansible, python-osism, inventory-reconciler). Added them to the SBOM repository.

SPDX files for kolla-images prepared, not yet pushed anywhere (because of the huge file size)

berendt commented 2 years ago

What still needs to be clarified here? The daily deployments will be changed this week. The rest is done.