Type:
Task
Priority:
Critical
Resolution:
Fixed
A customer is asking to extend SBOMs beyond their original goal of NTIA and executive order compliance. Apparently, own product and dependencies need to be have license and copyright statement.
copyright statement can be deduced automatically, so there must be some file that we can hardcode this information in.
License (as SPDX-id) can in theory be deduced by github APIs
Here is the rough plan -
the "machine-readable" file will be yaml-formatted. It consists of a yaml-list. i.e items starting with <dash>-name, every items has a couple of keys, license and maybe "copyright" if known, but also information we hardcoded elsewhere, e.g CPE identifier, or publisher. a cmake parser function will convert the list and they keys into a set of cmake variables, e.g THIRD_PARTY_ZLIB_LICENSE will be taken from
{"report":{"fcp":822,"ttfb":194.40000009536743,"pageVisibility":"visible","entityId":133510,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"f2c931c4-1bab-4cd6-9822-3a4dcc379aec","navigationType":0,"readyForUser":929.0999999046326,"redirectCount":0,"resourceLoadedEnd":529.5,"resourceLoadedStart":202.90000009536743,"resourceTiming":[{"duration":27.199999809265137,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bsh/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":202.90000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":202.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":230.09999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":27.300000190734863,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bsh/820016/12ta74/eb142f92e4bd16bd1ef8b08c1b9d5d56/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":203.09999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":203.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":230.40000009536743,"responseStart":0,"secureConnectionStart":0},{"duration":222,"initiatorType":"script","name":"https://jira.mariadb.org/s/b09d0d077992e4331b5f9ec0d3ec448c-CDN/lu2bsh/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":203.2000002861023,"connectEnd":203.2000002861023,"connectStart":203.2000002861023,"domainLookupEnd":203.2000002861023,"domainLookupStart":203.2000002861023,"fetchStart":203.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":232.7000002861023,"responseEnd":425.2000002861023,"responseStart":294.09999990463257,"secureConnectionStart":203.2000002861023},{"duration":97.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/6c569cbf8087ab04e40d0bef98627457-CDN/lu2bsh/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":203.40000009536743,"connectEnd":203.40000009536743,"connectStart":203.40000009536743,"domainLookupEnd":203.40000009536743,"domainLookupStart":203.40000009536743,"fetchStart":203.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":235,"responseEnd":300.90000009536743,"responseStart":296.7000002861023,"secureConnectionStart":203.40000009536743},{"duration":326.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/b47ab3df14096803b180217eb8482517-CDN/lu2bsh/820016/12ta74/eb142f92e4bd16bd1ef8b08c1b9d5d56/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":203.40000009536743,"connectEnd":203.40000009536743,"connectStart":203.40000009536743,"domainLookupEnd":203.40000009536743,"domainLookupStart":203.40000009536743,"fetchStart":203.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":234.7000002861023,"responseEnd":529.5,"responseStart":322.30000019073486,"secureConnectionStart":203.40000009536743},{"duration":97.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bsh/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":203.59999990463257,"connectEnd":203.59999990463257,"connectStart":203.59999990463257,"domainLookupEnd":203.59999990463257,"domainLookupStart":203.59999990463257,"fetchStart":203.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":235.59999990463257,"responseEnd":301.09999990463257,"responseStart":297.59999990463257,"secureConnectionStart":203.59999990463257},{"duration":97.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bsh/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":203.59999990463257,"connectEnd":203.59999990463257,"connectStart":203.59999990463257,"domainLookupEnd":203.59999990463257,"domainLookupStart":203.59999990463257,"fetchStart":203.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":237.30000019073486,"responseEnd":301.5,"responseStart":298.30000019073486,"secureConnectionStart":203.59999990463257},{"duration":32.19999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bsh/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":203.80000019073486,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":203.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":236,"responseStart":0,"secureConnectionStart":0},{"duration":97.80000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":203.90000009536743,"connectEnd":203.90000009536743,"connectStart":203.90000009536743,"domainLookupEnd":203.90000009536743,"domainLookupStart":203.90000009536743,"fetchStart":203.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":238.80000019073486,"responseEnd":301.7000002861023,"responseStart":299,"secureConnectionStart":203.90000009536743},{"duration":33.700000286102295,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bsh/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":204.09999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":204.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":237.80000019073486,"responseStart":0,"secureConnectionStart":0},{"duration":115.60000038146973,"initiatorType":"script","name":"https://jira.mariadb.org/s/81b5d7c27af3ebc078cc4a36383678ba-CDN/lu2bsh/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":204.09999990463257,"connectEnd":204.09999990463257,"connectStart":204.09999990463257,"domainLookupEnd":204.09999990463257,"domainLookupStart":204.09999990463257,"fetchStart":204.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":243.90000009536743,"responseEnd":319.7000002861023,"responseStart":299.80000019073486,"secureConnectionStart":204.09999990463257},{"duration":289.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bsh/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":204.90000009536743,"connectEnd":204.90000009536743,"connectStart":204.90000009536743,"domainLookupEnd":204.90000009536743,"domainLookupStart":204.90000009536743,"fetchStart":204.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":254.30000019073486,"responseEnd":494.09999990463257,"responseStart":489,"secureConnectionStart":204.90000009536743},{"duration":287.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bsh/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":207.7000002861023,"connectEnd":207.7000002861023,"connectStart":207.7000002861023,"domainLookupEnd":207.7000002861023,"domainLookupStart":207.7000002861023,"fetchStart":207.7000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":261.2000002861023,"responseEnd":494.90000009536743,"responseStart":491.2000002861023,"secureConnectionStart":207.7000002861023},{"duration":76,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":577.9000000953674,"connectEnd":577.9000000953674,"connectStart":577.9000000953674,"domainLookupEnd":577.9000000953674,"domainLookupStart":577.9000000953674,"fetchStart":577.9000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":620.0999999046326,"responseEnd":653.9000000953674,"responseStart":653,"secureConnectionStart":577.9000000953674},{"duration":144.7999997138977,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":815.2000002861023,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":815.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":960,"responseStart":0,"secureConnectionStart":0},{"duration":177,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":821.8000001907349,"connectEnd":821.8000001907349,"connectStart":821.8000001907349,"domainLookupEnd":821.8000001907349,"domainLookupStart":821.8000001907349,"fetchStart":821.8000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":966.0999999046326,"responseEnd":998.8000001907349,"responseStart":998.4000000953674,"secureConnectionStart":821.8000001907349}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":23,"responseStart":194,"responseEnd":207,"domLoading":198,"domInteractive":983,"domContentLoadedEventStart":983,"domContentLoadedEventEnd":1027,"domComplete":1440,"loadEventStart":1440,"loadEventEnd":1441,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":962.4000000953674},{"name":"bigPipe.sidebar-id.end","time":963.3000001907349},{"name":"bigPipe.activity-panel-pipe-id.start","time":963.4000000953674},{"name":"bigPipe.activity-panel-pipe-id.end","time":964.4000000953674},{"name":"activityTabFullyLoaded","time":1048.2000002861023}],"measures":[],"correlationId":"4aa0a5351c2065","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":84,"dbReadsTimeInMs":20,"dbConnsTimeInMs":27,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
there were discussions about machine-parseable license file that distros at some point wanted.
if we'll have that we can machine-parse it from cmake for SBOM