Skip to content

Conversation

@kikofernandez
Copy link
Contributor

@kikofernandez kikofernandez commented Nov 28, 2025

  • updates ORT to version 72.0.0, which makes us able to produce a SPDX version 2.3.
  • adds the OpenVex statements to the SBOM (which requires SPDX 2.3)

@kikofernandez kikofernandez self-assigned this Nov 28, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Nov 28, 2025

CT Test Results

  2 files   42 suites   16m 25s ⏱️
480 tests 476 ✅ 4 💤 0 ❌
568 runs  564 ✅ 4 💤 0 ❌

Results for commit 4cb56c4.

♻️ This comment has been updated with latest results.

To speed up review, make sure that you have read Contributing to Erlang/OTP and that all checks pass.

See the TESTING and DEVELOPMENT HowTo guides for details about how to run test locally.

Artifacts

// Erlang/OTP Github Action Bot

@kikofernandez kikofernandez force-pushed the kiko/sbom/update-spdx-sbom-to-2.3/OTP-19878 branch 3 times, most recently from 2d627ab to b4ef74e Compare November 28, 2025 13:14
@kikofernandez kikofernandez force-pushed the kiko/sbom/update-spdx-sbom-to-2.3/OTP-19878 branch 2 times, most recently from 5dd0420 to 2b23986 Compare November 28, 2025 20:02
@kikofernandez kikofernandez requested review from Whaileee and rickard-green and removed request for Whaileee November 29, 2025 06:08
@rickard-green rickard-green added the team:VM Assigned to OTP team VM label Dec 1, 2025
Whaileee
Whaileee previously approved these changes Dec 1, 2025
@kikofernandez kikofernandez force-pushed the kiko/sbom/update-spdx-sbom-to-2.3/OTP-19878 branch from c8b1127 to 174d97f Compare December 1, 2025 12:05
@kikofernandez kikofernandez changed the title update SPDX SBOM to 2.3 update SPDX SBOM to 2.3 and add openvex statements to SBOM Dec 1, 2025
@kikofernandez kikofernandez force-pushed the kiko/sbom/update-spdx-sbom-to-2.3/OTP-19878 branch 3 times, most recently from 6b90332 to 6492ed8 Compare December 1, 2025 13:27
Whaileee
Whaileee previously approved these changes Dec 1, 2025
@kikofernandez kikofernandez force-pushed the kiko/sbom/update-spdx-sbom-to-2.3/OTP-19878 branch from 4b1000c to 05ed81d Compare December 1, 2025 19:44
- updates ORT to version 72.0.0 to be able to produce a SPDX 2.3 version

- add MPL-1.1 to detected files

- add Mozilla Public License to test files detected by the file header
  script during SBOM creation. this is necessary to create a source SBOM,
  otherwise the build process of the source SBOM will continue failing.

- update dialyzer license on results

- add the OpenVex statements to the SBOM
update OpenVEX id to match file location

this is not mandatory in the spec but it makes sense that it coincides.
the update also makes the creation of new openvex files to match the new
IRI location.
@kikofernandez kikofernandez force-pushed the kiko/sbom/update-spdx-sbom-to-2.3/OTP-19878 branch from dd7030a to 4cb56c4 Compare December 1, 2025 21:24
@kikofernandez
Copy link
Contributor Author

kikofernandez commented Dec 2, 2025

There is an error with the cache scan-results.json, it contains duplicate provenance for the same scan result.
I am not sure yet where it goes wrong, but I am going to test if closing the PR and opening a new one makes the cache result to not be duplicate.

Follow up in #10428

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

team:VM Assigned to OTP team VM

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants