Skip to content

Conversation

maennchen
Copy link
Member

@maennchen maennchen commented Feb 13, 2025

Follow up of #14241

  • Declares Erlang Dependency
  • Declares elixir applications (required for purl to identify in case of elixir vulnerabilities)
  • Switches back to the official ORT action repo
  • Will pass the NTIA SBoM checker
  • The CI will inject the version info into the ORT config & SPDX file at runtime. The way this is implemented allows:
    • If somebody declares Elixir as a dependency, everything should scan as expected, but will not contain any version information
    • When the CI uses it, all version info is injected and present in the resulting SBoM
@maennchen maennchen marked this pull request as draft February 13, 2025 23:36
@maennchen
Copy link
Member Author

Actually I think there's one more simplification for the configuration. I'll put the PR into draft state until I know if it works.

@maennchen maennchen force-pushed the jm/spdx_multi branch 2 times, most recently from 6e81893 to 8586444 Compare February 14, 2025 00:10
@maennchen maennchen marked this pull request as ready for review February 14, 2025 00:11
@maennchen
Copy link
Member Author

Ready for review now :)

@josevalim josevalim merged commit 4b50edc into elixir-lang:main Feb 14, 2025
10 checks passed
@josevalim
Copy link
Member

💚 💙 💜 💛 ❤️

@maennchen maennchen deleted the jm/spdx_multi branch February 14, 2025 08:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants