mbox series

[v4,0/3] spdx: add support to include releaseTime

Message ID 20261002075414.2311840-1-daniel.turull@ericsson.com
Headers show
Series spdx: add support to include releaseTime | expand

Message

Daniel Turull Oct. 2, 2026, 7:54 a.m. UTC
From: Daniel Turull <daniel.turull@ericsson.com>

We have a requirements to include release time of open source components
in the SBOM. There is a field specific for that in spdx 3 spec.

https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/

This can also be used to evaluate how old are some of the core
components and decide if they need replacement.

The previous 2 versions did not have cover letter.

In v4 I kept the simpler logic to just check for the epoch date, even if
we have multiple sources with different release dates. It was getting
complicated and adding more code for git and tarfiles. I can do a follow
up patch after this simpler version gets in, so we can fine tune it.

Tested with oe-selftest -r spdx

Daniel Turull (3):
  classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash
  create-spdx-3.0: record component release date in SPDX output
  scripts/contrib: add spdx-release-date-report.py

 meta/classes-global/base.bbclass            |   4 +
 meta/lib/oe/spdx30_tasks.py                 |  22 +++
 meta/lib/oeqa/selftest/cases/spdx.py        |  41 +++++
 scripts/contrib/spdx-release-date-report.py | 191 ++++++++++++++++++++
 4 files changed, 258 insertions(+)
 create mode 100755 scripts/contrib/spdx-release-date-report.py