All of lore.kernel.org
 help / color / mirror / Atom feed
* SPDX delivery
@ 2024-05-15 17:11 Marta Rybczynska
  2024-05-15 18:08 ` Joshua Watt
  0 siblings, 1 reply; 8+ messages in thread
From: Marta Rybczynska @ 2024-05-15 17:11 UTC (permalink / raw)
  To: yocto, openembedded-architecture, Joshua Watt

[-- Attachment #1: Type: text/plain, Size: 907 bytes --]

Hello all,
As this discussion might be interesting to multiple people, I post it to YP
list and the OE architecture list.

In the VEX work (the status will go out in a moment in a separate message),
we're collecting SPDX and CVE files for builds to re-run the CVE checks
later (potentially months later). The CVE check file is generated for both
the image and the build as it is (including the SDK).

On the other hand, the SPDX archive is generated for the image only, and
contains only packages from the system image itself, omitting the build
system. This is possible for us to get all the partial SPDX files from the
build dir, but we do not expect the complete build dir to be kept for
months.

So, the question is, what people plan to archive from the build? Do we need
to archive the whole SPDX output too? This is an interesting question for
example in case of "world" builds..

Kind regards,
Marta

[-- Attachment #2: Type: text/html, Size: 1268 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2024-05-28 15:13 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-05-15 17:11 SPDX delivery Marta Rybczynska
2024-05-15 18:08 ` Joshua Watt
2024-05-16  7:26   ` Marta Rybczynska
2024-05-16  8:32     ` [Openembedded-architecture] " Esben Haabendal
2024-05-27 17:47   ` Marta Rybczynska
2024-05-27 23:01     ` Joshua Watt
2024-05-28 14:59       ` Marta Rybczynska
2024-05-28 15:13         ` Joshua Watt

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.