bytecodealliance / bytecodealliance/sample-wasi-http-rust

Extract the SBOM from Component and publish to the registry

Abierto
#54 0 comentarios 1 reacción 2 asignados Reclamado por @yoshuawuyts Ver en GitHub
enhancement
Lenguaje dominante
Rust
Estrellas
29
Forks
10
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

Once #53 lands and we've confirmed it works, the next step will be to extract the SBOM and publish it to the registry. I've filed https://github.com/bytecodealliance/wasm-pkg-tools/issues/154 to enable `wkg` to do this automatically, but we should get ahead of that and do start by doing it manually first.

To get the SBOM from the binary we have to install `auditable2cdx`, but currently that's blocked on https://github.com/rust-secure-code/cargo-auditable/issues/188. That should be easy enough for maintainers to resolve though, so we should be ok waiting on that. Once that lands I expect us to implement the following flow:

1. Extract the SBOM as CycloneDX-formatted JSON from the `.wasm` binary
3. Push and sign the SBOM on the registry using `cosign` ([guide](https://edu.chainguard.dev/open-source/sigstore/cosign/how-to-sign-an-sbom-with-cosign/))

To my knowledge there is nothing else we need to do here, but let me know if I've missed anything here. Thanks!

## References

- https://github.com/rust-secure-code/cargo-auditable/issues/188
- https://github.com/bytecodealliance/wasm-pkg-tools/issues/154
- [Chainguard - How to sign an SBOM with cosign](https://edu.chainguard.dev/open-source/sigstore/cosign/how-to-sign-an-sbom-with-cosign/)

##

cc/ @shnatsel, @thomastaylor312, and @phickey for awareness

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.