Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Restructure SPDX SBOMs to microsboms, matching ko #264

Merged
merged 2 commits into from
Jul 6, 2022

Conversation

puerco
Copy link
Contributor

@puerco puerco commented Jul 4, 2022

This PR modifies the SPDX SBOMs in the apko index and images to match the new system of micro sboms under discussion/development in ko-build/ko#655 and ko-build/ko#743

The base of this new approach is to ditch the all-encompassing SBOM broken into several documents and favor a micro SBOM ecosystem where the index does not link the the single image documents but references the images as external packages.

This is the new structure of the index (two arch images):

image

And the images:

image

This commit modifies the index SBOM structure to match the `ko` index
sboms. Namely, we drop the single sbom environment in favor of a
multiple micro-sbom ecosystem where each image and index have its own
sbom, not referencing other documents but just the images as packages.

Signed-off-by: Adolfo García Veytia (Puerco) <[email protected]>
This commit modifies the apko image sboms to match the ko sboms.

Signed-off-by: Adolfo García Veytia (Puerco) <[email protected]>
@kaniini kaniini merged commit fed231d into chainguard-dev:main Jul 6, 2022
@puerco puerco deleted the spdx-restructure branch July 8, 2022 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants