CycloneDX / CycloneDX/cyclonedx-rust-cargo

Capture data only available during the build process

Open
#532 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

cargo-cyclonedx enhancement
Dominant language
Rust
Stars
179
Forks
66
PR merge metrics
No merged PRs in 30d

Description

There is a certain amount of data that is only available during or after the actual build, such as a hash of the resulting binary, the RUSTFLAGS used (not just from the environment variable but also from the Cargo configuration), etc.

There are two ways to implement it:

  1. Hook into the build process, similar to how https://github.com/rust-secure-code/cargo-auditable works
  2. The hypothetical "build info" file that's being discussed by the Cargo team could be used to achieve this.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the requested build-time data: the resulting binary hash and the RUSTFLAGS from both the environment and Cargo configuration. Compare the cargo-auditable build-process hook with the hypothetical Cargo team “build info” file, then determine which approach can capture those values. Done means the selected approach records the requested build-only data.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
build-system
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.