public inbox for devel@edk2.groups.io
 help / color / mirror / Atom feed
From: "Richard Hughes via groups.io" <richard=hughsie.com@groups.io>
To: Dick Wilkins <Dick_Wilkins@phoenix.com>
Cc: "devel@edk2.groups.io" <devel@edk2.groups.io>,
	"leif.lindholm@oss.qualcomm.com" <leif.lindholm@oss.qualcomm.com>,
	"discuss@edk2.groups.io" <discuss@edk2.groups.io>,
	"Kinney, Michael D" <michael.d.kinney@intel.com>,
	Andrew Fish <afish@apple.com>
Subject: Re: [edk2-devel] SBOM template for edk2
Date: Mon, 16 Dec 2024 07:50:11 +0000	[thread overview]
Message-ID: <ecV-c-AUGAFqhzMiFlgWQ35lt08aO_pfduBIu_CJfQSvgRKoFlY71KGT8KOjh4ex2JFpwwN4u3YVUPRJCZIPQQAH-euutIGXH-law1OKWvw=@hughsie.com> (raw)
In-Reply-To: <BN0P223MB001542559A50D276C455F3BDEF3F2@BN0P223MB0015.NAMP223.PROD.OUTLOOK.COM>

Hi all,

If anyone wants a quick overview of where things are, and where things are heading -- there's some fairly self-explanatory slides in https://docs.google.com/presentation/d/1OPBHYZAr9SWDrmXpistJrVqd8wdN94oOfDfFXoEjTxg/edit?usp=sharing

If anyone does want me to explain all that in more detail please just ask, I'd be happy to explain the bigger picture -- or join the UEFI SBOM sub-team after Christmas and then you can ask questions to us all directly. :)

Richard

On Thursday, 12 December 2024 at 15:02, Dick Wilkins <Dick_Wilkins@phoenix.com> wrote:

> This is an ongoing discussion in the UEFI SBOM sub-team working group and we are aware of this PR. If you want feedback from that team, you can send email to usbt@uefi.org .
> 
> Dick
> 
> SBOM WG Vice-Chair
> 
> From: devel@edk2.groups.io <devel@edk2.groups.io> On Behalf Of Leif Lindholm via groups.io
> Sent: Thursday, December 12, 2024 6:33 AM
> To: devel@edk2.groups.io; discuss@edk2.groups.io
> Cc: Richard Hughes <richard@hughsie.com>; Kinney, Michael D <michael.d.kinney@intel.com>; Andrew Fish <afish@apple.com>
> Subject: [edk2-devel] SBOM template for edk2
> 
> [Caution, this message was sent from an external sender.]
> 
> Hi all,
> 
> Richard submitted a PR to add an SBOM .cdx.json template to the main repository:
> https://github.com/tianocore/edk2/pull/6455
> 
> This is a good thing, but I think we could do with some feedback from
> some of our
> downstream consumers.
> 
> I know there has been work ongoing inside UEFI forum around SBOM for
> UEFI firmware,
> and it might be useful for some of the people that have been more
> involved there to pitch
> in. Mike, do you know some appropriate people to ping?
> 
> /
> Leif
> 
> 
> 


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#120925): https://edk2.groups.io/g/devel/message/120925
Mute This Topic: https://groups.io/mt/110078030/7686176
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [rebecca@openfw.io]
-=-=-=-=-=-=-=-=-=-=-=-



      reply	other threads:[~2024-12-20 23:01 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-12-12 11:32 [edk2-devel] SBOM template for edk2 Leif Lindholm via groups.io
2024-12-12 15:02 ` Dick Wilkins via groups.io
2024-12-16  7:50   ` Richard Hughes via groups.io [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-list from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='ecV-c-AUGAFqhzMiFlgWQ35lt08aO_pfduBIu_CJfQSvgRKoFlY71KGT8KOjh4ex2JFpwwN4u3YVUPRJCZIPQQAH-euutIGXH-law1OKWvw=@hughsie.com' \
    --to=devel@edk2.groups.io \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox