Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve SBOM in future releases for laptops #962

Open
macpijan opened this issue Jul 24, 2024 · 5 comments
Open

Improve SBOM in future releases for laptops #962

macpijan opened this issue Jul 24, 2024 · 5 comments
Assignees
Labels
enhancement New feature or request novacustom_ns5x/7x_adl NovaCustom NS5x/7xPU (12th Gen) novacustom_ns5x/7x_tgl NovaCustom NS5x/7xMU (11th Gen) novacustom_ns7x_tgl NovaCustom NS7xMU (11th Gen) novacustom_nv4x_adl NovaCustom NV4xPZ (12th Gen) novacustom_nv4x_tgl NovaCustom NV4xMx (11th Gen) novacustom_v54_mtl NovaCustom V54 Series novacustom_v56_mtl NovaCustom V56 Series

Comments

@macpijan
Copy link
Contributor

The problem you're addressing (if any)

The SBOM information is limited to coreobot / edk2 revisions

Describe the solution you'd like

For some platforms, the SBOM information we provide is more extensive
Such as:
https://docs.dasharo.com/variants/protectli_vp46xx/releases/#v120-2024-03-25

Where is the value to a user, and who might that user be?

No response

Describe alternatives you've considered

No response

Additional context

No response

@macpijan macpijan added the enhancement New feature or request label Jul 24, 2024
@macpijan macpijan added novacustom_nv4x_tgl NovaCustom NV4xMx (11th Gen) novacustom_ns5x/7x_tgl NovaCustom NS5x/7xMU (11th Gen) novacustom_ns7x_tgl NovaCustom NS7xMU (11th Gen) novacustom_ns5x/7x_adl NovaCustom NS5x/7xPU (12th Gen) novacustom_nv4x_adl NovaCustom NV4xPZ (12th Gen) novacustom_v54_mtl NovaCustom V54 Series novacustom_v56_mtl NovaCustom V56 Series labels Jul 24, 2024
@BeataZdunczyk
Copy link
Member

@macpijan We are already addressing this as part of #955

Feature request: We provided links to all components' licenses at some point. I think that information should be included in SBOM's release notes. It has already happened a couple of times when someone asked about licenses for all components included. Maybe Opness Score should also account for that somehow.

@pietrushnic
Copy link

We should publish SBOMs in the Dasharo SBOM release section; those SBOMs should comply with the state of the art in a given project. The key question is how hard it would be to introduce that:

Maybe we should have a label for SBOM since we have more issues directly or indirectly related:

@krystian-hebel
Copy link

Not limited to laptops, but otherwise fits this issue: AFAICT none of the SBOMs list edk2-platforms, even though it is used by most of the platforms supported by Dasharo.

@mkopec
Copy link
Member

mkopec commented Nov 7, 2024

Tried to make some improvements for the upcoming release:

image

@mkopec
Copy link
Member

mkopec commented Nov 13, 2024

New release notes are now live: https://docs.dasharo.com/variants/novacustom_v540tnx/releases/#v091-2024-11-07

FSP and GOP are missing because they're not public, this needs to be fixed by publishing the blobs, then we can link to them in SBoM.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request novacustom_ns5x/7x_adl NovaCustom NS5x/7xPU (12th Gen) novacustom_ns5x/7x_tgl NovaCustom NS5x/7xMU (11th Gen) novacustom_ns7x_tgl NovaCustom NS7xMU (11th Gen) novacustom_nv4x_adl NovaCustom NV4xPZ (12th Gen) novacustom_nv4x_tgl NovaCustom NV4xMx (11th Gen) novacustom_v54_mtl NovaCustom V54 Series novacustom_v56_mtl NovaCustom V56 Series
Projects
Status: No status
Development

No branches or pull requests

5 participants