The firmware build can describe the third-party components that go into a
firmware image as a CycloneDX 1.6 software bill of
materials (SBOM). Releases ship one SBOM per firmware image, next to the
.pbz, .bin and .elf files.
The SBOM is not part of the default build. Build it on request, after configuring as usual:
pbl build sbom
This writes pebbleos.cdx.json to the build directory. The SBOM requires the
Ninja generator, which pbl configure uses.
The SBOM is derived from the build itself, so it lists exactly the components of the configured board and variant:
Ninja lists every input of pebbleos.elf (sources, objects, prebuilt
libraries, resources) and, from its dependency logs, every header each
object was compiled with.
Each file is matched against the component metadata (see below) by path. Files that belong to no component are PebbleOS’s own code.
Every matched component is listed with its version, supplier, license and, when available, its package URL (purl) and CPE.
The top-level component is the firmware image itself, with its version (from
git describe) and the SHA-256 and SHA-512 hashes of the firmware binary.
Generation fails if a file from outside the tree, for example a toolchain
header, belongs to no component, or if a file lies in a submodule’s own
nested third-party directory without a component of its own. This keeps
new dependencies from being left out silently.
Components are described in sbom.yml files:
third_party/sbom.yml: the submodules
fw/sbom.yml, lib/sbom.yml: third-party code kept in the tree
cmake/toolchain/sbom.yml: the toolchain runtime (C library, libgcc)
Each entry has these fields:
Field |
Description |
|---|---|
|
Component name, unique across all files. |
|
Files or directories, relative to the |
|
For toolchain components, a path relative to the toolchain root. |
|
Paths relative to the build directory, for components installed there. |
|
Subdirectories holding third-party code that needs its own component. |
|
Who supplies the component. |
|
SPDX license expression. Use |
|
Upstream version. Defaults to |
|
|
|
For components inside a submodule, the submodule commit. |
|
CycloneDX component type: |
|
Identifiers for vulnerability databases. |
|
Upstream repository or website. |
|
Short description. |
The commit of every component inside a submodule must match the commit the
submodule points to. When updating a submodule, update its version,
commit and purl too. CI checks this on every pull request, as well as that
every submodule is described. To run the same check locally:
python3 tools/cmake/sbom.py check
New submodules and third-party code copied into the tree need an entry in the
nearest sbom.yml.
Generated from PebbleOS 91af4a22c. This page is maintained in the pebbleos repository: docs/development/sbom.md.