fix(packaging): support larger container SBOM attestations

Gazebo ROS image publication exceeds BuildKit 0.32's 40 MiB attestation limit. Pin the builder daemon to 0.33.0 for its 80 MiB limit while preserving the existing scanner and complete package/file coverage.

Assisted-by: Copilot:gpt-6-astra
This commit is contained in:
Ramon Roche
2026-09-10 17:49:41 -07:00
parent a9817844ec
commit 61907962c9
2 changed files with 4 additions and 0 deletions
+2
View File
@@ -166,6 +166,8 @@ jobs:
id: buildx
with:
driver: docker-container
# Gazebo/ROS SBOMs exceed the 40 MiB attestation limit in BuildKit 0.32.
driver-opts: image=moby/buildkit:v0.33.0
platforms: linux/${{ matrix.arch }}
- name: Restore ROS compiler cache
@@ -186,6 +186,8 @@ Installing the complete source-build toolset increases cold image-build time and
## Container SBOMs
The publishing workflow enables BuildKit's standard SBOM attestations for both runtime and ROS images.
It pins BuildKit v0.33.0, whose 80 MiB attestation limit accommodates the Gazebo/ROS SPDX documents without reducing their package or file coverage.
Local attested builds using BuildKit v0.32 can fail at export because that version limits each attestation to 40 MiB.
These SPDX inventories describe discoverable packages in the image filesystem, including Ubuntu and ROS dependencies.
They complement, rather than replace, PX4's [source and firmware SBOM](../contribute/sbom.md).