Skip to content

Conversation

@SchlegNi
Copy link

@SchlegNi SchlegNi commented Dec 1, 2025

With this PR west spdx will include the information about the modules from zephyr.meta into the SBOM as default values, and override this values if a module has defined a security entry in its module.yml file.
With this change, the modules-deps.spdx would represent which versions are actually used. And tools like dependency-track are able to track used packages by the purl entry.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Hello @SchlegNi, and thank you very much for your first pull request to the Zephyr project!
Our Continuous Integration pipeline will execute a series of checks on your Pull Request commit messages and code, and you are expected to address any failures by updating the PR. Please take a look at our commit message guidelines to find out how to format your commit messages, and at our contribution workflow to understand how to update your Pull Request. If you haven't already, please make sure to review the project's Contributor Expectations and update (by amending and force-pushing the commits) your pull request if necessary.
If you are stuck or need help please join us on Discord and ask your question there. Additionally, you can escalate the review when applicable. 😊

@sonarqubecloud
Copy link

sonarqubecloud bot commented Dec 1, 2025

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants