Add SBOM + support multiple machines #11

Merged
schwan merged 4 commits from WIP/l.anderweit@phytec.de/updates into scarthgap 2026-08-18 13:39:19 +02:00
Member

Build CycloneDX SBOM
Add compiled kernel sources to SPDX SBOM
Include machine name in basename
Mask meta-imx wifi firmware bbappend

Build CycloneDX SBOM Add compiled kernel sources to SPDX SBOM Include machine name in basename Mask meta-imx wifi firmware bbappend
Build a CycloneDX SBOM with cyclonedx-export from meta-cyclonedx. Add
the layer to the layer dependencies.

Signed-off-by: Leonard Anderweit <l.anderweit@phytec.de>
Enable SPDX_INCLUDE_COMPILED_SOURCES to add the name of all compiled
sources to the SPDX SBOM. This will be used to filter out kernel CVEs
that are in files which are not compiled.

Signed-off-by: Leonard Anderweit <l.anderweit@phytec.de>
Include $MACHINE in $IMAGE_BASENAME as a workaround for phyhub which
doesn't accept the same image name for multiple machines.
Also, set IMAGE_MACHINE_SUFFIX empty so the machine name doesn't show up twice
in the final image name

Signed-off-by: Leonard Anderweit <l.anderweit@phytec.de>
meta-freescale adds wifi firmware to PACKAGES that meta-imx adds as
well. This leads to an

<packagename> is listed in PACKAGES multiple times, this leads to
packaging errors

error. Ignore the bbappend in meta-imx.

This is already fixed for imx8mp in meta-phytec.

Signed-off-by: Leonard Anderweit <l.anderweit@phytec.de>
schwan approved these changes 2026-08-18 13:39:15 +02:00
schwan merged commit a8c1ff9aa8 into scarthgap 2026-08-18 13:39:19 +02:00
schwan deleted branch WIP/l.anderweit@phytec.de/updates 2026-08-18 13:39:19 +02:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
phytec/meta-liot!11
No description provided.