FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[3.12] gh-112302: Backport SBOM generation tooling by sethmlarson · Pull Request #114730 · python/cpython · GitHub

/ cpython Public

[3.12] gh-112302: Backport SBOM generation tooling - #114730

Merged
Yhg1s merged 1 commit into
python:3.12from
sethmlarson:3.12-sbom
Feb 6, 2024
Merged

[3.12] gh-112302: Backport SBOM generation tooling#114730
Yhg1s merged 1 commit into
python:3.12from
sethmlarson:3.12-sbom

Conversation

sethmlarson commented Jan 29, 2024
edited
Loading

Copy link
Copy Markdown
Contributor

This PR backports the following PRs to the 3.12 branch which has an identical SBOM to the main branch. 3.11 and earlier all have substantial differences (by including setuptools which has multiple layers of dependency vendoring). I proposed backporting to previous branches on discuss.python.org.

As a data point to limit fear of breaking builds of downstream distributors, we received feedback from @befeleme in #114240 and #114244 which appear to have been resolved in #114450.

sethmlarson added skip news 3.12 only security fixes labels Jan 29, 2024
sethmlarson changed the title gh-112302: [3.12] Backport SBOM generation tooling [3.12] gh-112302: Backport SBOM generation tooling Jan 29, 2024
sethmlarson marked this pull request as ready for review January 29, 2024 19:08

hugovk commented Feb 6, 2024

Copy link
Copy Markdown
Member

Does this need updating following #115038?

I'm fine with this going in 3.12, do you think it needs RM approval?

Copy link
Copy Markdown
Contributor Author

@hugovk Yes this will need that update applied to this branch, and I indeed want to get approval from release managers, I'll send this again to Thomas today.

Yhg1s merged commit 5e64828 into python:3.12 Feb 6, 2024
sethmlarson deleted the 3.12-sbom branch February 6, 2024 18:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.12 only security fixes skip news

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL