pnoltes commented on PR #845: URL: https://github.com/apache/celix/pull/845#issuecomment-5897793291
> Ubuntu regularly provides safety upgrades so that our normal Ubuntu build (via apt) is generally safe. However, using lockfile this way prevents automatic software update, and we will be forced to update the lockfile frequently to provide safe defaults, which seems an unnecessary burden. Considering SBOM only takes one Conan command to generate, I think we'd better leave it to the downstream users. > I do think we can proactively audit our dependencies in our CI. After setting up an audit provider properly, a single command will provide very informative report like the following: I am struggling a bit with this. With our current setup, we do provide a conanfile.py (which also includes some version/version-range restrictions), and you can build Celix with Ubuntu packages. I can understand that we say/document something like: "The latest Ubuntu packages from the LTS used in Apache Celix are our reference for monitoring upstream vulnerabilities. Usage of Conan is also possible, but it is up to the user to resolve/select the final dependency versions." And maybe document how you can run a conan audit scan. In this case, I would expect that, if we do something with SBOM generation and vulnerability scanning, we do it based on the APT-based CI builds. Alternatively, we could make Conan and Conan package version resolution our reference and use a lockfile. I think it is also Ok to update the lockfile more frequently, and at the same time a lockfile could help during heavy development to prevent too many dependency changes between builds. I am a bit worried about the maintenance burden once we have more insight into upstream vulnerabilities. So I am not sure what the best approach is. From a "minimize the burden" perspective, I think it would be better to follow the APT package approach and rely on Canonical LTS security maintenance, instead of depending on multiple Conan Center recipes and therefore multiple maintainers. Maybe something with `syft` is possible and then scanning the CI build dir. For me, the main question is therefore which dependency ecosystem we want to treat as the reference security baseline for Apache Celix. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
