All of lore.kernel.org
 help / color / mirror / Atom feed
* [bitbake-devel][PATCH] fetch: Upgrade shown checksum to SHA-512
@ 2026-05-13 14:46 Joshua Watt
  2026-05-13 20:21 ` Alexander Kanavin
  2026-05-14  6:55 ` Richard Purdie
  0 siblings, 2 replies; 4+ messages in thread
From: Joshua Watt @ 2026-05-13 14:46 UTC (permalink / raw)
  To: bitbake-devel; +Cc: Joshua Watt

Regulatory standards for Software Bill of Materials like BSI TR-03183
[1] are requiring SHA 512 as the minimum checksum for validation.
Upgrade the checksum suggested by the bitbake fetcher to align with this
requirement.

Note that the checker has allowed SHA 512 as the checksum for some time
now, this only changes the checksum that is suggested by tooling.

[1]: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03183/TR-03183_node.html

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
---
 lib/bb/fetch2/__init__.py | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/bb/fetch2/__init__.py b/lib/bb/fetch2/__init__.py
index f7d5dfe9a..1e78c4fda 100644
--- a/lib/bb/fetch2/__init__.py
+++ b/lib/bb/fetch2/__init__.py
@@ -35,7 +35,7 @@ _revisions_cache = bb.checksum.RevisionsCache()
 logger = logging.getLogger("BitBake.Fetcher")
 
 CHECKSUM_LIST = [ "goh1", "md5", "sha256", "sha1", "sha384", "sha512" ]
-SHOWN_CHECKSUM_LIST = ["sha256"]
+SHOWN_CHECKSUM_LIST = ["sha256", "sha512"]
 
 class BBFetchException(Exception):
     """Class all fetch exceptions inherit from"""
-- 
2.54.0



^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-05-14  6:55 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-05-13 14:46 [bitbake-devel][PATCH] fetch: Upgrade shown checksum to SHA-512 Joshua Watt
2026-05-13 20:21 ` Alexander Kanavin
2026-05-13 21:13   ` Joshua Watt
2026-05-14  6:55 ` Richard Purdie

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.