<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/xback/scripts/make-sbom.py, branch master</title>
<subtitle>Staging tree of Koen Vandeputte</subtitle>
<id>https://git-03.infra.openwrt.org/openwrt/staging/xback/atom?h=master</id>
<link rel='self' href='https://git-03.infra.openwrt.org/openwrt/staging/xback/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/openwrt/staging/xback/'/>
<updated>2026-09-22T16:46:30Z</updated>
<entry>
<title>build: create reproducible CycloneDX SBOMs</title>
<updated>2026-09-22T16:46:30Z</updated>
<author>
<name>John Crispin</name>
</author>
<published>2026-09-21T19:56:35Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/openwrt/staging/xback/commit/?id=712ff7ca89f76f6fdcb3289f78b7176174013a1e'/>
<id>urn:sha1:712ff7ca89f76f6fdcb3289f78b7176174013a1e</id>
<content type='text'>
Both SBOM generators produce a different file on every run, so the
published .bom.cdx.json of an image and of a package feed never match a
rebuild.

dump_cyclonedxsbom_json() in scripts/package-metadata.pl has three
causes. It draws the serial number from rand(), it takes the timestamp
from the wall clock, and encode_json() follows the Perl hash order, which
changes with the hash seed of each run. The last one alone reorders every
key in the file.

scripts/make-sbom.py has the first two causes, through uuid.uuid4() and
datetime.utcnow().

Take the timestamp from SOURCE_DATE_EPOCH, which the build exports. Derive
the serial number from the timestamp and the component list, so it stays a
valid RFC 4122 identifier and still changes when the content changes. Sort
the keys of the Perl output.

Tested with the package index and the image manifest of an ipq40xx build.
Two runs with the same SOURCE_DATE_EPOCH are now identical, two runs with
different values differ, and the scripts exit with an error when the value
is not a number. Both files differ between two runs without the change.

Signed-off-by: John Crispin &lt;john@phrozen.org&gt;
</content>
</entry>
<entry>
<title>scripts: fix CycloneDX BOM version type</title>
<updated>2026-09-07T07:58:43Z</updated>
<author>
<name>Cui Shuang</name>
</author>
<published>2026-09-06T07:25:04Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/openwrt/staging/xback/commit/?id=67eb69a1ae0a9defc6f08c14b2979ba67c000a42'/>
<id>urn:sha1:67eb69a1ae0a9defc6f08c14b2979ba67c000a42</id>
<content type='text'>
CycloneDX 1.4 requires the top-level BOM version to be an integer.
Emit numeric 1 so SBOMs generated from both APK and opkg package
indexes conform to the schema.

Signed-off-by: Cui Shuang &lt;imcusg@gmail.com&gt;
Link: https://github.com/openwrt/openwrt/pull/25059
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
</content>
</entry>
<entry>
<title>build: add CycloneDX SBOM processing to apk</title>
<updated>2026-05-17T10:21:09Z</updated>
<author>
<name>Florian Eckert</name>
</author>
<published>2025-09-30T12:49:52Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/openwrt/staging/xback/commit/?id=10d9dbe838447b79a616cf4b0e149b7e398df46a'/>
<id>urn:sha1:10d9dbe838447b79a616cf4b0e149b7e398df46a</id>
<content type='text'>
Currently, there is no SBOM generation in imagebuilder when the package
system 'apk' is used. This commit adds this feature back. This already
worked for the package system 'opkg'.

Furthermore, generating the SBOM using perl is not reproducible if the
input data has not changed. A different file is always generated. This is
not the case with Python. For this reason, Python is now used to generate
the SBOM for the imagebuilder.

The script has already been prepared so that it can also process the opkg
package system for generating the SBOM.

Signed-off-by: Florian Eckert &lt;fe@dev.tdt.de&gt;
</content>
</entry>
</feed>
