elisa-tech / wg-systems

The Systems WG aims to enable other working groups within ELISA to put their safety claims towards Linux in a wider system context. It encourages interactions with other open source projects related to ELISA project use cases or functional safety in open source in general.
Creative Commons Attribution Share Alike 4.0 International
3 stars 2 forks source link

Generte the full system SBOM for the end2end example #5

Open pahmann opened 1 year ago

pahmann commented 1 year ago

The AGL needlefish already can generate the SBOM using yocto tooling. A full system SBOM should also include Xen and Zephyr. In this task it should be checked, how to generate the SBOM for Xen and Zephyr. It may include to build Xen and Zephyr directly in yocto rahter than with e.g. west as for Zephyr. If the demo can be built with all elements created from Yocto the SBOM generation may become easier and consistent.

pahmann commented 4 months ago

This can be a good topic after qemu system is reproducible.

pahmann commented 2 months ago

Drafting first thoughts inside this document: https://docs.google.com/document/d/12jcC9CrGHlYwLBlFql6VLCsOmcl63paih2kj_1J55D