I will discuss an experiment with leveraging the CMake file-based APIs to automatically create SPDX 2.2 SBoMs. The generated SBoM includes relationships to denote which source files were used as inputs for the corresponding build artifacts. I will present this in the context of the Zephyr project, an open source RTOS for embedded systems that leverages CMake. I will briefly discuss this proof-of-concept, some early results from it and thoughts for next steps.
Type | devroom |
---|
2/7/21 |
Welcome to the Software Composition Analysis Devroom
|
2/7/21 |
In this session we will provide an update on OSS Review Toolkit (ORT) - which features have been recently added and what they ORT team is currently working on.
|
2/7/21 |
This is a presentation of the latest features and updates in ScanCode toolkit.
|
2/7/21 |
FOSSology focusses on license compliance analyses. Recently, a number of new features have been published by the community to integrate better with software composition analysis. The presentation shows an introduction of the main and relevant development here.
|
2/7/21 |
Software Composition Analysis (SCA) tools perform source-code analysis, comparison and identification of Open Source components. Sadly, none of the SCA vendors have embraced Open Source themselves, most of their tooling consists of proprietary code and their OSS Knowledge Bases are also closed.
|
2/7/21 |
Container and VM images contain many packages and are quite a challenge for composition analysis.
|
2/7/21 |
The very short time is some placeholder between presentation groups to have questions being asked and answered or just simple to have a break.
|