Skip to content

Add Software Bill-of-Materials for Windows source dependencies #112844

Description

@sethmlarson

Proposal:

Part of #112302

An SBOM document has been added for dependencies within CPython itself. This document is kept up-to-date using tooling and CI within the CPython repository. For building the Windows there exists a repository cpython-source-deps which "mirrors" the source code of projects not in the CPython git repo.

These dependencies are pulled in optionally, I still need to investigate what combinations are possible, but I know the possible projects and versions for each CPython branch is captured currently in PCBuild/get_externals.bat.

Will be investigating what the best method for creating an SBOM for these dependencies such that release-tools can stitch it into the final SBOMs that are distributed with release artifacts. There's a chance that no work needs to be done on this repository, in that case this issue will be migrated.

cc @zooba @ned-deily @ambv

Has this already been discussed elsewhere?

See the Discourse topic

Linked PRs

Activity

  1. ned-deily commented on Dec 7, 2023

    @ned-deily
    Member

    FTR, historically, macOS installer builds do not use cpython-source-deps and there are no plans to do so. That repo was created specifically for Windows builds and has contained patches to various upstream releases (like here) that might not apply to other platforms and doesn't contain patches that may be needed on other platforms like for the macOS installer.

  2. sethmlarson commented on Dec 7, 2023

    @sethmlarson
    ContributorAuthor

    @ned-deily That's good to know that these sources are patched! Ack on macOS, I must have misremembered something else.

  3. zooba commented on Dec 8, 2023

    @zooba
    Member

    FTR, I have no concerns about that repo containing patches for other platforms. Virtually all the time those patches are taken from upstream, so they'll work everywhere.

    When we patch, we add another tag with an extra version field (e.g. the 8.6.13**.1** I just tagged for Tcl and Tk). And a particular release of Python should always pull from a tag, and those are only listed in get_externals.bat (there are other references in some of the .props files, but those aren't as easy to parse out).

  4. added a commit that references this issue on Feb 29, 2024
  5. added a commit that references this issue on Feb 29, 2024
  6. added a commit that references this issue on Feb 29, 2024
  7. added a commit that references this issue on Mar 4, 2024
  8. added a commit that references this issue on Mar 25, 2024
  9. added a commit that references this issue on Apr 16, 2024
  10. added a commit that references this issue on Apr 16, 2024
  11. added a commit that references this issue on Apr 16, 2024
  12. added 2 commits that reference this issue on Apr 17, 2024
  13. added a commit that references this issue on May 2, 2024
  14. sethmlarson commented on May 8, 2024

    @sethmlarson
    ContributorAuthor

    Going to close this issue as we now have Windows SBOMs containing source dependencies for 3.13.0b1 🥳

  15. added a commit that references this issue on May 20, 2024
  16. added 2 commits that reference this issue on May 20, 2024
  17. added 2 commits that reference this issue on May 20, 2024
  18. added a commit that references this issue on Jul 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions