BuildStream SBOM generator
This tool can be used to produce an SBoM (Software Bill of Materials) describing a BuildStream element and its dependencies. It currently generates SPDX version 2.3.
The manifest contains useful information, such as the package name, version, source locations and dependencies.
Source provenance data
This tool relies on the Source Provenance API introduced in BuildStream 2.5. This API is implemented by buildstream-plugins version 2.5.0 and buildstream-plugins-community 2.1.0. Please make sure your project is using those (or more recent) versions. If your project uses custom source plugins, please make sure that they also implement this API.
Version guessing is handled by individual source plugins, please check the individual plugin documentation for details. Most plugins that implement it do something similar to what DownloadableFileSource does, so it is a good starting point for understanding how this works.
The list of currently supported source provenance attributes that can be specified and used for a Buildstream project is as follows:
| Attribute name | Corresponding SPDX attribute |
|---|---|
| concluded-license | licenseConcluded |
| copyright-text | copyrightText |
| declared-license | licenseDeclared |
| description | summary |
| homepage | homepage |
| name | name |
| originator | originator |
| supplier | supplier |
These can be used in projects by use of the source-provenance-attributes
field in the project.conf, this is described in the provenance section of
the BuildStream documentation.
source-provenance-attributes snippet
# project.conf
source-provenance-attributes:
concluded-license: The license as determined by the evidence provided by the source project
copyright-text: Copyright text defined by the source project
declared-license: The license of the source project as decided by the authors
description: Description of the source project
homepage: The URL of the source project's homepage
name: The name of the source project
originator: The name of the person or organisation that created the source package originally
supplier: The name of the person or organisation that provided the source package
Should any BuildStream plugins implement tracking for source provenance attributes, similar to source tracking, it is recommended for all projects and plugins to use the attribute names exactly as seen above. This ensures the source provenance attributes are always generated identically between different plugins and makes sure they align with projects' definitions in the same way.
Usage
To install, clone this repository and install it using pip (or preferably a
tool like uv tool or
pipx which install it in a virtual
environment).
To use, run buildstream-sbom in a buildstream project passing in the name of
elements like you would pass to bst. There are two additional required
arguments --spdx-name and --spdx-namespace, to set the SPDX document name
and document namespace respectively. See the SPDX specification
for details.
buildstream-sbom also accepts some buildstream options, notably -o/--option
to set buildstream options, -C/--directory to set the directory containing
the buildstream project, and --deps to choose whether to include only runtime
dependencies or all dependencies.
On the topic of runtime dependencies, two BuildStream core plugins are treated
specially: filter and compose. All build dependencies of elements using
these plugins are considered runtime dependencies. You can set the depends-on
key in the sbom public domain data to a list of build dependencies to have
buildstream-sbom treat these build dependencies as runtime dependencies. This
is useful for a script or manual element that copies artifacts from a build
dependency into its own artifact.
You can also include licenses that have been extracted from the element's
artifacts using --with-licenses. This uses license information installed
with tooling such as Freedesktop-SDK's install-extra script. This option can
also be used in conjunction with --artifact-checkout-directory (-A), to
control where element artifacts are checked out to during processing; useful
for if you are checking out larger artifacts and want to specify a different
part of a filesystem with more available space (note that artifacts are removed
once processed anyway to minimise required storage space).
There is also support for vulnerability scanning via the
--with-known-vulnerabilities flag, which can also work offline if a local
database is provided through --vulnerability-database. This will perform a
scan with your specified scanning tool, and include any results in the SPDX.
Metadata
Release files for buildstream-sbom 1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| buildstream_sbom-1.2.tar.gz | 18.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| buildstream_sbom-1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 32.0 kB
Release files / buildstream_sbom-1.2.tar.gz
| Download URL | buildstream_sbom-1.2.tar.gz |
|---|---|
| Size | 18.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
75140d3bbf4282956c8783a92b508f998ec9040e352df94dabe0aface635c6ad
|
|
BLAKE2b-256 checksum How to use checksums |
e7e100165edc04f720357f54b00879bda09defb6ebe5d43db6fcfeb4a0d9627b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|
Release files / buildstream_sbom-1.2-py3-none-any.whl
| Download URL | buildstream_sbom-1.2-py3-none-any.whl |
|---|---|
| Size | 13.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
fbdd9d4034b01bf0e61c898b8749f576bc74af189eb9ce578711e30d13da1013
|
|
BLAKE2b-256 checksum How to use checksums |
152ea2741515ccc41ea466e89c7c6eeaa1bb9c0f1fc84f68644c2634cae96ce2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|