Hey Josh,

I have been roadmapping SBOM generation for NI's yocto distro and have a few open questions about the future of SPDX and the create-spdx bbclass. Since your name seems to be attached to both of those, I figure you might have the best insight here.

Also posting to the OE-core ML so that this discussion can help other members.


1. SPDX 3 timeline. I hear that SPDX 3 is going to be a complete rewrite of the spec, with more support for modern SBOM discussion topics like VEX and more comprehensive vulnerability tracking. And it also seems to me that the timeline for its release is very behind schedule [1], but still in active development. Can you give a SWAG for how close that new spec is to completion? Are we months away or years?

2. If/when SPDX 3 support is released, is it to be assumed that the SPDX facilities in OE core are going to be upgraded to handle it?

3. The rest of my org is interested in CycloneDX as our common SBOM format. Have there been any discussions about supporting CDX SBOMs in OE-core? Any blockers there; or is it something that my org could author and upstream if we decide to go that route?


[1] https://github.com/spdx/spdx-spec/milestone/3


Appreciate the input,

--
Alex Stewart
Software Engineer - NI Real-Time OS
NI (National Instruments)

alex.stew...@ni.com

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#176750): 
https://lists.openembedded.org/g/openembedded-core/message/176750
Mute This Topic: https://lists.openembedded.org/mt/96729387/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to