Collaborative Working Sessions - SBOM for rpm

SBOM discussion led by Marek

rpmbuild should produce buildinfo file during package-build

currently fragmented: OBS, koji, others reinvent their own formats

There was previous discussion with rpm maintainers. Idea: produce separate sub-package with that buildinfo file. format was too Debian-ish and therefore disliked by rpm maintainers.

buildinfo-rpm can be signed the normal way can be published to separate repo (similar to debuginfo)

Prior work:



result/output-SBOM vs input/build-SBOM => see also notes on Wed discussion on SBOM SPDX + CycloneDX + in-toto file format

consumers for SBOM files:

missing link for publishing required buildrequires rpm + fetching via name|shasum