python / python/cpython

Update SBOM generation to meet new guidance from CISA

Ouverte
#123,038 4 commentaires 1 réaction 1 personne assignée Voir sur GitHub

@sethmlarson y travaille déjà.

Depuis le 15/8/2024.

triaged type-security
Langage dominant
Python
Étoiles
77.2k
Forks
35.9k
Métriques de merge des PR
Métriques de PR en attente

Description

Proposal:

CISA has published the third revision of SBOM guidance, which at the moment isn't approved but is headed towards final rounds of review. Currently our SBOMs met the old revision which is "Minimum Elements of an SBOM" published by NTIA.

The new guidance uses a "maturity level", ranging from minimum required to aspirational. Below I've used the "aspirational" maturity level for all the criteria.

I checked our SBOM documents against the document to see how much would be needed to follow this new set of guidance. It turns out, not too much! Here's the breakdown:

Elements that need more work:
  • Author Name: We need to add an email address
  • SBOM Type: We need to upgrade to SPDX 3 for this field
  • Supplier Name: Need to double-check that these names conform. Also need to update where we add Heritage information.
  • Unique Identifier: We're almost there, there's at least one project we should request a CPE for.
  • Heritage: We don't encode this information today. Some of our components are slightly modified from upstream dependency, should be automatable.
  • Relationship Completeness
  • License
  • Copyright Notice
Elements we already conform with:
  • Timestamp
  • Primary Component
  • Component Name
  • Component Version
  • Cryptographic Hashes
  • Relationships
  • Redacted and Unknown Components and Attributes
Has this already been discussed elsewhere?

This is a minor feature, which does not need previous discussion elsewhere

Links to previous discussion of this feature:

No response

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.