-
Notifications
You must be signed in to change notification settings - Fork 7
Open
Labels
enhancementNew feature or requestNew feature or request
Description
Once #53 lands and we've confirmed it works, the next step will be to extract the SBOM and publish it to the registry. I've filed bytecodealliance/wasm-pkg-tools#154 to enable wkg
to do this automatically, but we should get ahead of that and do start by doing it manually first.
To get the SBOM from the binary we have to install auditable2cdx
, but currently that's blocked on rust-secure-code/cargo-auditable#188. That should be easy enough for maintainers to resolve though, so we should be ok waiting on that. Once that lands I expect us to implement the following flow:
- Extract the SBOM as CycloneDX-formatted JSON from the
.wasm
binary - Push and sign the SBOM on the registry using
cosign
(guide)
To my knowledge there is nothing else we need to do here, but let me know if I've missed anything here. Thanks!
References
- Publish
auditable2cdx
0.1.0 rust-secure-code/cargo-auditable#188 - Support automatically uploading SBOMs wasm-pkg-tools#154
- Chainguard - How to sign an SBOM with cosign
cc/ @Shnatsel, @thomastaylor312, and @phickey for awareness
thomastaylor312
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request