Skip to content

Conversation

@maennchen
Copy link
Member

@maennchen maennchen commented Feb 13, 2025

Follow up of #14241

  • Declares Erlang Dependency
  • Declares elixir applications (required for purl to identify in case of elixir vulnerabilities)
  • Switches back to the official ORT action repo
  • Will pass the NTIA SBoM checker
  • The CI will inject the version info into the ORT config & SPDX file at runtime. The way this is implemented allows:
    • If somebody declares Elixir as a dependency, everything should scan as expected, but will not contain any version information
    • When the CI uses it, all version info is injected and present in the resulting SBoM

@maennchen maennchen marked this pull request as draft February 13, 2025 23:36
@maennchen
Copy link
Member Author

Actually I think there's one more simplification for the configuration. I'll put the PR into draft state until I know if it works.

@maennchen maennchen force-pushed the jm/spdx_multi branch 2 times, most recently from 6e81893 to 8586444 Compare February 14, 2025 00:10
@maennchen maennchen marked this pull request as ready for review February 14, 2025 00:11
@maennchen
Copy link
Member Author

Ready for review now :)

@josevalim josevalim merged commit 4b50edc into elixir-lang:main Feb 14, 2025
10 checks passed
@josevalim
Copy link
Member

💚 💙 💜 💛 ❤️

@maennchen maennchen deleted the jm/spdx_multi branch February 14, 2025 08:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants