Skip to content

[Umbrella] Bill of Materials #1837

@puerco

Description

@puerco

We intend to ensure the quality and integrity of the artifacts produced on each release cut by adding a Bill of Materials (BOM). The BOM will be published in SPDX and will include integrity and licensing information for the artifacts we produce. Work on this area will lead to close other outstanding issues (linked here).

Following our road-mapping session, this umbrella issue will track the development to create the BOM.

Make krel aware of binary artifacts expected from the release process:

Note: These items are postponed as we delayed the supported platforms effort to 1.23+

Verify/process binary artifacts as the release process advances from stage to stage

Write SPDX manifest(s). Output should include data about:

Publish the SPDX manifests with the other release artifacts:

Make our tools available community-wide

/cc @hasheddan @xmudrii @markyjackson-taulia

Metadata

Metadata

Assignees

Labels

area/release-engIssues or PRs related to the Release Engineering subprojectarea/release-eng/securityIssues or PRs related to release engineering securitykind/featureCategorizes issue or PR as related to a new feature.priority/important-soonMust be staffed and worked on either currently, or very soon, ideally in time for the next release.

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions