WH Theme: SBOMS / Notifications
Other background:
Draft ASF Position:
- SBOMs needs to be automatically generated for builds at build time
- SBOMs need to be signed with the same keys used for releases, in the same way (detached signature, detached hash)
- SBOMs are expected to be static to the given release, must never be changed after release
- SBOMs need to be useful (i.e. can be parsed, machine readable by current/future tools)
Questions
- What type of projects/builds should include SBOMs?
- What format should be used (e.g., SPDX, CycloneDX)
- What projects are interested in working on this?
- ARROW Java: Publish SBOM artifacts (Maven, CycloneDX, published)
- AVRO-3700: Publish SBOM artifacts (Maven, CycloneDX)
- Commons https://github.com/apache/commons-parent/pull/122 (Maven, CycloneDX, published for some)
- DRUID: Publish SBOM artifacts (Maven, CycloneDX, merged)
- FLINK-30578: Publish SBOM artifacts (Maven, CycloneDX, published)
- HADOOP-18590. Publish SBOM artifacts (Maven, CycloneDX, merged)
- HIVE-26912: Publish SBOM artifacts (Maven, CycloneDX, merged)
- HBASE-27562 Publish SBOM artifacts (Maven, CycloneDX, published)
- Maven MPOM-346: publish SBOM on release (Maven, CycloneDX)
- ORC-1342: Publish SBOM artifacts (Maven, CycloneDX, published)
- PARQUET-2224: Publish SBOM artifacts (Maven, CycloneDX, published)
- SPARK-41893: Publish SBOM artifacts (Maven, CycloneDX, published)
- SYNCOPE-1746: Provide Software Bill Of Materials (SBOM) (Maven, CycloneDX, published)
- ZOOKEEPER-4657: Publish SBOM artifacts (Maven, CycloneDX, published)