conda / conda/ceps

CEP: SBOM for package contents

Open
#127 14 comments 6 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
34
Forks
41
Avg merge
1h 46m
Merged PRs (30d)
1

Description

While we strive to avoid vendored dependencies in conda packages, they still happen under certain circumstances, e.g.

- If a specific commit of a C/C++ Library is required
- For languages where vendoring/static linkage is the norm: Haskell, Rust, Go, JavaScript

In these situations, the conda package metadata does not sufficiently cover the actual package contents. This situation is often described as having [Phantom Dependencies](https://www.endorlabs.com/learn/dependency-resolution-in-python-beware-the-phantom-dependency). While some languages (e.g. Go) already contain sufficient information in the binary itself, it is costly to extract them. Thus, we should precompute them during the build, where we have the full dependency information

The generated SBOMs should be part of the files installed into the environment so that SBOM generation tools can generate high-quality SBOMs from the environment itself without the need to parse repodata or have a specialized tool for conda.

## Implementation Idea (for rattler)

I would really like if rattler-build had a flag to generate an SBOM from package contents. It could be as simple as running syft over the directory. But already having the metadata computed once from the binares would save a lot of time. E.g. for a typical go binary, it took me 8s to do binary inspection with syft. If an SBOM were already present, this would be a matter of milliseconds.

Once we have decided where we want to put the SBOM in the package, pixi could have a pixi sbom that extracts the SBOM from the packages and uses the pixi.lock information itself to generate an SBOM.

My initial idea:
- Compute SBOMs as part (or after) of the package build
- Store them as part of the package, but ensure it ends up in `conda-meta/` on installation
- If someone wants to generate an SBOM of a conda environment, it should be sufficient to run the tool on top of the conda-meta folder (e.g. in the case of `syft`, using only the conda and the SBOM cataloguer).
- Only generate SBOMs for packages that vendor something, not for all.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.