CycloneDX / CycloneDX/cyclonedx-python

[IDEA] feat: library mode

未关闭
#1,041 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
Python
星标
392
派生
99
平均合并
2 天 23 小时
30 天内合并 PR
2

描述

## Is your feature request related to a problem? Please describe.

if i build a SBOM for a **library**, i do not want to have non-bundled component listed as if they were concrete.
These dependencies are extraneous/"external" and the version of them is not clear - it is resolved on install-time .
Also, transitive dependencies of those are not clear until install-time.

This should be reflected in the SBOM.

## Describe the solution you'd like

Spec:

add a way to have
- only the bundled dependencies and the direct dependencies as components in the SBOM result.
- to be discussed, as python packaging does not declare this at the moment - see in contrast PEP770
- non-bundled' components must have no version.
- non-bundled's components must have a version range - [specification#321]
- non-bundled are marked as "external" - [specification#321]
- the dependency composition completeness is set to "incomplete_first_party_only" - see https://cyclonedx.org/guides/OWASP_CycloneDX-Authoritative-Guide-to-SBOM-en.pdf page 59

## UX

to be discussed - see https://github.com/CycloneDX/cyclonedx-python/issues/1041#issuecomment-4250137234

### option to exisitng subcomamnds

option could be called (list of ideas)
- `--library-mode`
- `--mark-extraneous`/`--mark-externals`
- add your idea in the comments

new option MUST imply `--omit dev`

new option MUST be disabled bu default
new option MUST be marked as experimental in help page
new option might set `--mc-type=library'


### Describe alternatives you've considered

- instead of adding an option to existing sub-commands, we might add a specific sub command. -- to be discussed.
- we could make it, so that the existing option `--mc-type=library' causes this behavior by default, but that would be a breaking change

### Additional context

for libraries, non-bundled components are "external" - this is discussed in [specification#321]

`pyrproject.toml` knows the concept of
- platdform-depenedncies -- #597
- direct-dependencies
- optional dependencies (might be controlled by "extras")
- dev-dependencies - no intention to be shipped.
might shadow all of the above on build-time

the library-moed SBOM genertated by the tool might be merged with an extra SBOM to create an entire SBOM for PEP770

## Contribution

- [ ] I am willing to provide an implementation
- [x] I will wait until somebody else implements it

[specification#321]: https://github.com/CycloneDX/specification/issues/321

贡献指南

打开贡献指南

调研方向

首先检查现有的子命令和选项处理,然后阅读CycloneDX规范 issue #321以及链接的UX讨论。设计必须确定命令或选项、它与--omit dev和--mc-type=library的交互方式,以及如何将pyproject.toml中的依赖类别映射到SBOM。完成的标准是实验模式采用opt-in,并输出指定的外部组件和incomplete_first_party_only composition。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
需要澄清
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。