Skip to content

PHPLIB-1447: Add SBOM lite #1292

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 8, 2024
Merged

Conversation

alcaeus
Copy link
Member

@alcaeus alcaeus commented May 8, 2024

PHPLIB-1447

Since we don't have any bundled dependencies, we can add an empty SBOM file

@alcaeus alcaeus requested a review from jmikola May 8, 2024 09:38
@alcaeus alcaeus requested a review from a team as a code owner May 8, 2024 09:38
@alcaeus alcaeus force-pushed the phplib-1447-sbom-lite branch from aaa1d60 to 9218537 Compare May 8, 2024 09:52
Copy link
Member

@jmikola jmikola left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll trust this is the correct format for an empty SBOM file, but I'm curious how it was generated. Ideally, we should make a note of that either in this PR or PHPLIB-1447 in case we ever need to refer back to this.

},
{
"vendor": "cyclonedx",
"name": "cyclonedx-php-composer",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file looks generated. Where did you get it from?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The file was generated using the cyclonedx/cyclonedx-php-composer library to generate an SBOM from composer.lock, then manually removing all components and dependencies as we only report bundled dependencies:

composer require --dev cyclonedx/cyclonedx-php-composer
composer CycloneDX:make-sbom --output-file=sbom.json --output-format=JSON --omit=dev --omit=plugin

@alcaeus alcaeus merged commit ef9cbfc into mongodb:v1.18 May 8, 2024
24 checks passed
@alcaeus alcaeus deleted the phplib-1447-sbom-lite branch May 8, 2024 14:17
alcaeus added a commit that referenced this pull request May 10, 2024
* v1.18: (50 commits)
  Enable auto-merge in merge-up workflow (#1295)
  PHPLIB-1447: Add SBOM lite (#1292)
  Fix syntax error in docs (#1285)
  PHPLIB-1163 Create tutorial for using MongoDB with Bref (#1273) (#1282)
  Create sarif report when running psalm (#1280)
  Update composer.json and CI matrices for 1.18.0
  PHPLIB-1410: Invoke drivers-evergreen-tools scripts with bash (#1267)
  PHPLIB-1302: Use Composer\InstalledVersions (#1262)
  PHPLIB-1320: Support "comment" command option in Collection::createIndex() (#1263)
  PHPLIB-1413: Use env instead of matrix for driver-version (#1261)
  Fix Markdown heading
  PHPLIB-1399: Docs examples for agg expr projection (#1260)
  PHPLIB-1412: Skip range encryption tests on MongoDB 8.0+ (#1259)
  PHPLIB-1409: Skip $out and mapReduce tests on serverless (#1254)
  Exclude read-write-concern tests from serverless testing (#1253)
  PHPLIB-1409: Convert default write concern tests to unified test format (#1252)
  PHPLIB-1408: Convert ADL spec test to unified test format (#1250)
  Remove redundant annotations (#1251)
  PHPLIB-1404: Convert retryable reads spec tests to unified test format  (#1247)
  DOCSP-36627: Additional double backslash fixes for master (#1246)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants