pnoltes commented on PR #845:
URL: https://github.com/apache/celix/pull/845#issuecomment-5897793291

   > Ubuntu regularly provides safety upgrades so that our normal Ubuntu build 
(via apt) is generally safe. However, using lockfile this way prevents 
automatic software update, and we will be forced to update the lockfile 
frequently to provide safe defaults, which seems an unnecessary burden. 
Considering SBOM only takes one Conan command to generate, I think we'd better 
leave it to the downstream users.
   
   > I do think we can proactively audit our dependencies in our CI. After 
setting up an audit provider properly, a single command will provide very 
informative report like the following:
   
   I am struggling a bit with this. With our current setup, we do provide a 
conanfile.py (which also includes some version/version-range restrictions), and 
you can build Celix with Ubuntu packages.
   
   I can understand that we say/document something like: "The latest Ubuntu 
packages from the LTS used in Apache Celix are our reference for monitoring 
upstream vulnerabilities. Usage of Conan is also possible, but it is up to the 
user to resolve/select the final dependency versions." And maybe document how 
you can run a conan audit scan. In this case, I would expect that, if we do 
something with SBOM generation and vulnerability scanning, we do it based on 
the APT-based CI builds.
   
   Alternatively, we could make Conan and Conan package version resolution our 
reference and use a lockfile. I think it is also Ok to update the lockfile more 
frequently, and at the same time a lockfile could help during heavy development 
to prevent too many dependency changes between builds.
   
   I am a bit worried about the maintenance burden once we have more insight 
into upstream vulnerabilities. So I am not sure what the best approach is. From 
a "minimize the burden" perspective, I think it would be better to follow the 
APT package approach and rely on Canonical LTS security maintenance, instead of 
depending on multiple Conan Center recipes and therefore multiple maintainers. 
Maybe something with `syft` is possible and then scanning the CI build dir. 
   
   For me, the main question is therefore which dependency ecosystem we want to 
treat as the reference security baseline for Apache Celix. 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to