Details
-
Type:
Change
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: None
-
Fix Version/s: V3.5.1.0
-
Component/s: None
-
Labels:
-
Sprint:PI4_IT2 (28.10.-8.11.)
-
Account:SPC Object Dictionary (SPCOBJECTD)
Description
integrate SBOM
- Update to waf V1.13.2.0 (waf documentation can be found in the "Documentation" folder within the waf component itself)
- Update to Static Code Analysis V1.0.5.0, if used.
- Update to AsciiDoc V1.0.5.0, if used.
- Update Qemu Test environement to V0.0.20.0
- Adapt Jenkins file so that Jenkins calls "waf2 configure build ..." instead of "waf configure build ...".
Documentation can be found here:
https://hilscher.atlassian.net/wiki/spaces/GPS/pages/148433778/Jenkins+Pipeline+User+Documentation#JenkinsPipelineUserDocumentation-Configuringbuildtoolfordefaultbuildflow:~:text=%7D-,Configuring%20build%20tool%20for%20default%20build%20flow,-Use - Add a source sbom.json file to the project and activate the SBOM generation by following the instructions in the waf documentation
(see section "Handling CycloneDX SBOM")
If this component/firmware makes use of third party source code, ensure this information is also included on the SBOM source file
(see waf documentation, section "Incorporating more information in SBOM").