Skip to main content

BuildStream SBOM generator

This tool can be used to produce an SBoM (Software Bill of Materials) describing a BuildStream element and its dependencies. It currently generates SPDX version 2.3.

The manifest contains useful information, such as the package name, version, source locations and dependencies.

Source provenance data

This tool relies on the Source Provenance API introduced in BuildStream 2.5. This API is implemented by buildstream-plugins version 2.5.0 and buildstream-plugins-community 2.1.0. Please make sure your project is using those (or more recent) versions. If your project uses custom source plugins, please make sure that they also implement this API.

Version guessing is handled by individual source plugins, please check the individual plugin documentation for details. Most plugins that implement it do something similar to what DownloadableFileSource does, so it is a good starting point for understanding how this works.

The list of currently supported source provenance attributes that can be specified and used for a Buildstream project is as follows:

Attribute name Corresponding SPDX attribute
concluded-license licenseConcluded
copyright-text copyrightText
declared-license licenseDeclared
description summary
homepage homepage
name name
originator originator
supplier supplier

These can be used in projects by use of the source-provenance-attributes field in the project.conf, this is described in the provenance section of the BuildStream documentation.

source-provenance-attributes snippet

# project.conf

source-provenance-attributes:
  concluded-license: The license as determined by the evidence provided by the source project
  copyright-text: Copyright text defined by the source project
  declared-license: The license of the source project as decided by the authors
  description: Description of the source project
  homepage: The URL of the source project's homepage
  name: The name of the source project
  originator: The name of the person or organisation that created the source package originally
  supplier: The name of the person or organisation that provided the source package

Should any BuildStream plugins implement tracking for source provenance attributes, similar to source tracking, it is recommended for all projects and plugins to use the attribute names exactly as seen above. This ensures the source provenance attributes are always generated identically between different plugins and makes sure they align with projects' definitions in the same way.

Usage

To install, clone this repository and install it using pip (or preferably a tool like uv tool or pipx which install it in a virtual environment).

To use, run buildstream-sbom in a buildstream project passing in the name of elements like you would pass to bst. There are two additional required arguments --spdx-name and --spdx-namespace, to set the SPDX document name and document namespace respectively. See the SPDX specification for details.

buildstream-sbom also accepts some buildstream options, notably -o/--option to set buildstream options, -C/--directory to set the directory containing the buildstream project, and --deps to choose whether to include only runtime dependencies or all dependencies.

On the topic of runtime dependencies, two BuildStream core plugins are treated specially: filter and compose. All build dependencies of elements using these plugins are considered runtime dependencies. You can set the depends-on key in the sbom public domain data to a list of build dependencies to have buildstream-sbom treat these build dependencies as runtime dependencies. This is useful for a script or manual element that copies artifacts from a build dependency into its own artifact.

You can also include licenses that have been extracted from the element's artifacts using --with-licenses. This uses license information installed with tooling such as Freedesktop-SDK's install-extra script. This option can also be used in conjunction with --artifact-checkout-directory (-A), to control where element artifacts are checked out to during processing; useful for if you are checking out larger artifacts and want to specify a different part of a filesystem with more available space (note that artifacts are removed once processed anyway to minimise required storage space).

There is also support for vulnerability scanning via the --with-known-vulnerabilities flag, which can also work offline if a local database is provided through --vulnerability-database. This will perform a scan with your specified scanning tool, and include any results in the SPDX.

Metadata

Release files for buildstream-sbom 1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for buildstream-sbom 1.2
File Size Uploaded
buildstream_sbom-1.2.tar.gz 18.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for buildstream-sbom 1.2
File Interpreter ABI Platform
buildstream_sbom-1.2-py3-none-any.whl Python 3 none any Details

Total release size: 32.0 kB

Release files / buildstream_sbom-1.2.tar.gz

Download URL buildstream_sbom-1.2.tar.gz
Size 18.3 kB
Tags Source
SHA-256 checksum
How to use checksums
75140d3bbf4282956c8783a92b508f998ec9040e352df94dabe0aface635c6ad
BLAKE2b-256 checksum
How to use checksums
e7e100165edc04f720357f54b00879bda09defb6ebe5d43db6fcfeb4a0d9627b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / buildstream_sbom-1.2-py3-none-any.whl

Download URL buildstream_sbom-1.2-py3-none-any.whl
Size 13.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fbdd9d4034b01bf0e61c898b8749f576bc74af189eb9ce578711e30d13da1013
BLAKE2b-256 checksum
How to use checksums
152ea2741515ccc41ea466e89c7c6eeaa1bb9c0f1fc84f68644c2634cae96ce2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

This release

1.2 This release

2 release files

1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page