A customer is asking to extend SBOMs beyond their original goal of NTIA and executive order compliance. Apparently, own product and dependencies need to be have license and copyright statement.
copyright statement can be deduced automatically, so there must be some file that we can hardcode this information in.
License (as SPDX-id) can in theory be deduced by github APIs
there were discussions about machine-parseable license file that distros at some point wanted.
if we'll have that we can machine-parse it from cmake for SBOM
Sergei Golubchik
added a comment - there were discussions about machine-parseable license file that distros at some point wanted.
if we'll have that we can machine-parse it from cmake for SBOM
People
Vladislav Vaintroub
Vladislav Vaintroub
Votes:
0Vote for this issue
Watchers:
2Start watching this issue
Dates
Created:
Updated:
Git Integration
Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.
{"report":{"fcp":1200.6000003814697,"ttfb":269.6000003814697,"pageVisibility":"visible","entityId":133510,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"e56958fa-6735-44a2-ac59-0c86aec19632","navigationType":0,"readyForUser":1251.3000001907349,"redirectCount":0,"resourceLoadedEnd":1452,"resourceLoadedStart":275.30000019073486,"resourceTiming":[{"duration":41.90000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":275.30000019073486,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":275.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":317.2000002861023,"responseStart":0,"secureConnectionStart":0},{"duration":41.799999713897705,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":275.7000002861023,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":275.7000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":317.5,"responseStart":0,"secureConnectionStart":0},{"duration":391,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":275.90000009536743,"connectEnd":275.90000009536743,"connectStart":275.90000009536743,"domainLookupEnd":275.90000009536743,"domainLookupStart":275.90000009536743,"fetchStart":275.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":275.90000009536743,"responseEnd":666.9000000953674,"responseStart":666.9000000953674,"secureConnectionStart":275.90000009536743},{"duration":474.2000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":276,"connectEnd":276,"connectStart":276,"domainLookupEnd":276,"domainLookupStart":276,"fetchStart":276,"redirectEnd":0,"redirectStart":0,"requestStart":276,"responseEnd":750.2000002861023,"responseStart":750.2000002861023,"secureConnectionStart":276},{"duration":478.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":276.2000002861023,"connectEnd":276.2000002861023,"connectStart":276.2000002861023,"domainLookupEnd":276.2000002861023,"domainLookupStart":276.2000002861023,"fetchStart":276.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":276.2000002861023,"responseEnd":754.3000001907349,"responseStart":754.2000002861023,"secureConnectionStart":276.2000002861023},{"duration":479.2000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":276.5,"connectEnd":276.5,"connectStart":276.5,"domainLookupEnd":276.5,"domainLookupStart":276.5,"fetchStart":276.5,"redirectEnd":0,"redirectStart":0,"requestStart":276.5,"responseEnd":755.7000002861023,"responseStart":755.7000002861023,"secureConnectionStart":276.5},{"duration":479.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":276.7000002861023,"connectEnd":276.7000002861023,"connectStart":276.7000002861023,"domainLookupEnd":276.7000002861023,"domainLookupStart":276.7000002861023,"fetchStart":276.7000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":276.7000002861023,"responseEnd":756.1000003814697,"responseStart":756.1000003814697,"secureConnectionStart":276.7000002861023},{"duration":539.9000000953674,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":276.90000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":276.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":816.8000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":479.5,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":277.1000003814697,"connectEnd":277.1000003814697,"connectStart":277.1000003814697,"domainLookupEnd":277.1000003814697,"domainLookupStart":277.1000003814697,"fetchStart":277.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":277.1000003814697,"responseEnd":756.6000003814697,"responseStart":756.6000003814697,"secureConnectionStart":277.1000003814697},{"duration":539.6999998092651,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":277.2000002861023,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":277.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":816.9000000953674,"responseStart":0,"secureConnectionStart":0},{"duration":480.30000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":277.40000009536743,"connectEnd":277.40000009536743,"connectStart":277.40000009536743,"domainLookupEnd":277.40000009536743,"domainLookupStart":277.40000009536743,"fetchStart":277.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":277.40000009536743,"responseEnd":757.7000002861023,"responseStart":757.7000002861023,"secureConnectionStart":277.40000009536743},{"duration":996.4000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":278.30000019073486,"connectEnd":278.30000019073486,"connectStart":278.30000019073486,"domainLookupEnd":278.30000019073486,"domainLookupStart":278.30000019073486,"fetchStart":278.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":278.30000019073486,"responseEnd":1274.7000002861023,"responseStart":1274.7000002861023,"secureConnectionStart":278.30000019073486},{"duration":1173.5999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":278.40000009536743,"connectEnd":278.40000009536743,"connectStart":278.40000009536743,"domainLookupEnd":278.40000009536743,"domainLookupStart":278.40000009536743,"fetchStart":278.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":278.40000009536743,"responseEnd":1452,"responseStart":1452,"secureConnectionStart":278.40000009536743},{"duration":445.80000019073486,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":829.3000001907349,"connectEnd":829.3000001907349,"connectStart":829.3000001907349,"domainLookupEnd":829.3000001907349,"domainLookupStart":829.3000001907349,"fetchStart":829.3000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":829.3000001907349,"responseEnd":1275.1000003814697,"responseStart":1275.1000003814697,"secureConnectionStart":829.3000001907349},{"duration":296.90000009536743,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":1171,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1171,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1467.9000000953674,"responseStart":0,"secureConnectionStart":0},{"duration":209.60000038146973,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":1304,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1304,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1513.6000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":209.19999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/50bc9be5bfead1a25e72c1a9338c94f6-CDN/lu2cib/820016/12ta74/e108c7645258ccb43280ed3404e3e949/_/download/contextbatch/css/com.atlassian.jira.plugins.jira-development-integration-plugin:0,-_super,-jira.view.issue,-jira.global,-jira.general,-jira.browse.project,-project.issue.navigator,-atl.general/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":1304.6000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1304.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1513.8000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":181.80000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":1305.8000001907349,"connectEnd":1305.8000001907349,"connectStart":1305.8000001907349,"domainLookupEnd":1305.8000001907349,"domainLookupStart":1305.8000001907349,"fetchStart":1305.8000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":1305.8000001907349,"responseEnd":1487.6000003814697,"responseStart":1487.6000003814697,"secureConnectionStart":1305.8000001907349}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":133,"responseStart":269,"responseEnd":271,"domLoading":273,"domInteractive":1473,"domContentLoadedEventStart":1473,"domContentLoadedEventEnd":1513,"domComplete":2972,"loadEventStart":2972,"loadEventEnd":2974,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1453.8000001907349},{"name":"bigPipe.sidebar-id.end","time":1454.7000002861023},{"name":"bigPipe.activity-panel-pipe-id.start","time":1454.9000000953674},{"name":"bigPipe.activity-panel-pipe-id.end","time":1455.9000000953674},{"name":"activityTabFullyLoaded","time":1527}],"measures":[],"correlationId":"60eb21445e6139","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":80,"dbReadsTimeInMs":9,"dbConnsTimeInMs":16,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
there were discussions about machine-parseable license file that distros at some point wanted.
if we'll have that we can machine-parse it from cmake for SBOM