mirror of
https://github.com/lvgl/lvgl.git
synced 2026-10-02 10:23:47 +08:00
docs(cra): add SBOM for CRA complience (#10352)
This commit is contained in:
@@ -29,7 +29,9 @@ jobs:
|
||||
python-version: 3.12
|
||||
|
||||
- name: Install dependencies
|
||||
run: python3 -m pip install kconfiglib pytest
|
||||
# sbom/requirements.txt pins the SBOM validator so an unreviewed
|
||||
# upstream release cannot silently change or break the compliance gate.
|
||||
run: python3 -m pip install kconfiglib pytest -r sbom/requirements.txt
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Unit tests for the config-headers generator itself.
|
||||
@@ -57,6 +59,28 @@ jobs:
|
||||
include/lvgl/config/lv_conf_kconfig.h \
|
||||
|| (echo "::error::Generated config headers are out of date. Run scripts/generators/config_headers.py and commit the result."; exit 1)
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# COPYRIGHTS.md and the SPDX SBOM (sbom/) are generated from
|
||||
# sbom/third_party.json. These fail if a committed output is stale.
|
||||
# ------------------------------------------------------------------
|
||||
- name: "Check: COPYRIGHTS.md is up to date"
|
||||
id: copyrights
|
||||
continue-on-error: true
|
||||
run: python3 scripts/generate_copyrights.py --check
|
||||
|
||||
- name: "Check: SPDX SBOM is up to date"
|
||||
id: sbom
|
||||
continue-on-error: true
|
||||
run: python3 scripts/generate_sbom.py --check
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# The SBOM validates against the official SPDX 3.0.1 JSON Schema.
|
||||
# ------------------------------------------------------------------
|
||||
- name: "Check: SPDX SBOM is schema-valid"
|
||||
id: sbom_schema
|
||||
continue-on-error: true
|
||||
run: python3 scripts/validate_sbom.py
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Final gate – fail the job if any generator above is out of date.
|
||||
# This gives us full output from every generator before failing.
|
||||
@@ -65,7 +89,10 @@ jobs:
|
||||
- name: "Gate: fail if any generator check failed"
|
||||
if: |
|
||||
steps.config-headers-tests.outcome == 'failure' ||
|
||||
steps.config-headers.outcome == 'failure'
|
||||
steps.config-headers.outcome == 'failure' ||
|
||||
steps.copyrights.outcome == 'failure' ||
|
||||
steps.sbom.outcome == 'failure' ||
|
||||
steps.sbom_schema.outcome == 'failure'
|
||||
run: |
|
||||
echo "Code generation results:"
|
||||
echo "------------------------"
|
||||
@@ -81,6 +108,9 @@ jobs:
|
||||
|
||||
print_result "config-headers-tests" "${{ steps.config-headers-tests.outcome }}"
|
||||
print_result "config-headers" "${{ steps.config-headers.outcome }}"
|
||||
print_result "copyrights" "${{ steps.copyrights.outcome }}"
|
||||
print_result "sbom" "${{ steps.sbom.outcome }}"
|
||||
print_result "sbom_schema" "${{ steps.sbom_schema.outcome }}"
|
||||
|
||||
echo "------------------------"
|
||||
echo "A generator test failed, or a generated file is out of date. See above for details."
|
||||
|
||||
@@ -9,7 +9,7 @@ on:
|
||||
# https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#concurrency
|
||||
# Ensure that only one commit will be running tests at a time on each PR
|
||||
concurrency:
|
||||
group: ${{ github.ref }}-${{ github.workflow }}
|
||||
group: ${{ github.ref }}-${{ github.workflow }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
@@ -42,7 +42,7 @@ jobs:
|
||||
# ------------------------------------------------------------------
|
||||
# - All #includes inside must be valid relative paths.
|
||||
# - Angle-bracket includes must be in the explicit allow-list
|
||||
# - see `ALLOWED_EXTERNAL_HEADERS` in `scripts/static_checks/check_headers.py`
|
||||
# - see `ALLOWED_EXTERNAL_HEADERS` in `scripts/static_checks/check_headers.py`
|
||||
# - forbidden headers (stdint.h etc.) must use LV_*_INCLUDE macros.
|
||||
# ------------------------------------------------------------------
|
||||
- name: "Check: include path validity + angle-bracket policy"
|
||||
@@ -67,7 +67,7 @@ jobs:
|
||||
run: python scripts/static_checks/check_headers.py deprecated
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Every header file inside `src` must use `lvgl_public.h` to access
|
||||
# Every header file inside `src` must use `lvgl_public.h` to access
|
||||
# the public API
|
||||
# ------------------------------------------------------------------
|
||||
- name: "Check: no direct public include from source files"
|
||||
|
||||
+35
-14
@@ -1,67 +1,88 @@
|
||||
LVGL uses the following third-party libraries.
|
||||
For the licenses, see the corresponding `LICENSE.txt` file in each library’s folder.
|
||||
Each entry lists its SPDX license expression below. The full license text is, for most libraries, found in the corresponding library folder (see the paths); some libraries only reference their license rather than shipping the full text. A machine-readable inventory is available in `sbom/`.
|
||||
|
||||
**Barcode (Barcode generator)**
|
||||
- Path: src/libs/barcode
|
||||
- Source: https://github.com/fhunleth/code128
|
||||
|
||||
**Expat (XML parser)**
|
||||
- Path: src/libs/expat
|
||||
- Source: https://github.com/libexpat/libexpat
|
||||
- License: BSD-2-Clause
|
||||
|
||||
**FreeType (Font rendering library)**
|
||||
- Path: src/libs/freetype
|
||||
- Source: https://github.com/freetype/freetype
|
||||
- License: FTL OR GPL-2.0-or-later
|
||||
- Note: Only the interfaces are used; FreeType itself is not part of LVGL.
|
||||
|
||||
**Liberation Sans (default demo font)**
|
||||
- Path: src/libs/freetype/LiberationSans-Regular.ttf
|
||||
- Source: https://github.com/liberationfonts/liberation-fonts
|
||||
- License: OFL-1.1
|
||||
- Note: Font asset bundled alongside the FreeType interface; licensed separately from FreeType.
|
||||
|
||||
**LodePNG (PNG decoder)**
|
||||
- Path: src/libs/lodepng
|
||||
- Source: https://github.com/lvandeve/lodepng
|
||||
- License: Zlib
|
||||
|
||||
**LZ4 (Compression/Decompression)**
|
||||
- Path: src/libs/lz4
|
||||
- Source: https://github.com/lz4/lz4
|
||||
- License: BSD-2-Clause
|
||||
|
||||
**QR Code (QR code generator)**
|
||||
- Path: src/libs/qrcode
|
||||
- Source: https://github.com/nayuki/QR-Code-generator
|
||||
- License: MIT
|
||||
|
||||
**ThorVG (Vector graphics rendering)**
|
||||
- Path: src/libs/thorvg
|
||||
- Source: https://github.com/thorvg/thorvg
|
||||
- License: MIT
|
||||
|
||||
**RapidJSON (JSON parser/generator)**
|
||||
- Path: src/libs/thorvg/rapidjson
|
||||
- Source: https://github.com/Tencent/rapidjson
|
||||
- License: MIT AND BSD-3-Clause
|
||||
- Note: Bundled inside the ThorVG tree (used by ThorVG's Lottie parser); licensed separately from ThorVG. The bundled msinttypes helper (rapidjson/msinttypes) is BSD-3-Clause (Copyright (c) 2006-2013 Alexander Chemeris), hence the combined license expression.
|
||||
|
||||
**TinyTTF**
|
||||
- Path: src/libs/tiny_ttf
|
||||
- Source:
|
||||
- https://github.com/nothings/stb (*Only parts are integrated*)
|
||||
- https://github.com/codewitch-honey-crisis/tiny_ttf (*Modified version of the original STB library*)
|
||||
- https://github.com/nothings/stb (*Only parts are integrated*)
|
||||
- https://github.com/codewitch-honey-crisis/tiny_ttf (*Modified version of the original STB library*)
|
||||
- License: MIT OR Unlicense
|
||||
|
||||
**TJPGD (JPEG decoder)**
|
||||
- Path: src/libs/tjpgd
|
||||
- Source: http://elm-chan.org/fsw/tjpgd/00index.html
|
||||
- License: LicenseRef-TJpgDec
|
||||
|
||||
**TLSF (Two-Level Segregate Fit memory allocator)**
|
||||
- Path: src/stdlib/builtin
|
||||
- Source: https://github.com/mattconte/tlsf
|
||||
- License: BSD-3-Clause
|
||||
|
||||
**Printf (Printf formatting library)**
|
||||
- Path: src/stdlib/builtin
|
||||
- Source: https://github.com/mpaland/printf
|
||||
|
||||
**LVGL's XML format**
|
||||
- Path:
|
||||
- docs/src/auxiliary-modules/xml
|
||||
- src/others/xml
|
||||
- xmls
|
||||
- License: MIT
|
||||
|
||||
**FT800-FT813 (EVE GPU driver)**
|
||||
- Path src/libs/FT800-FT813
|
||||
- Path: src/libs/FT800-FT813
|
||||
- Source: https://github.com/RudolphRiedel/FT800-FT813
|
||||
- License: MIT
|
||||
|
||||
**AnimatedGIF (GIF decoder library)**
|
||||
- Path: src/libs/gif
|
||||
- Source: https://github.com/bitbank2/AnimatedGIF
|
||||
- License: Apache-2.0
|
||||
|
||||
**NanoVG (Anti-aliased vector graphics rendering)**
|
||||
- Path: src/libs/nanovg
|
||||
- Source: https://github.com/memononen/nanovg
|
||||
- License: Zlib
|
||||
- Note: Compiled when LV_USE_NANOVG (or the LV_USE_DRAW_NANOVG backend) is enabled.
|
||||
|
||||
**FrogFS (read-only filesystem)**
|
||||
- Path: src/libs/frogfs
|
||||
- Source: https://github.com/jkent/frogfs
|
||||
- License: MPL-2.0
|
||||
|
||||
+35
@@ -0,0 +1,35 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
**Please do not open a public GitHub issue for security problems.**
|
||||
|
||||
Report suspected vulnerabilities privately by email to
|
||||
**security@lvgl.io**.
|
||||
|
||||
Please include, as far as you can:
|
||||
|
||||
- the affected version(s) and configuration (`lv_conf.h` toggles, target),
|
||||
- a description of the impact,
|
||||
- steps to reproduce or a proof of concept, and
|
||||
- any suggested fix or mitigation.
|
||||
|
||||
We support coordinated disclosure: please give us a reasonable window to
|
||||
release a fix before any public disclosure. We will credit you in the advisory
|
||||
unless you prefer otherwise.
|
||||
|
||||
## Supported versions
|
||||
|
||||
Fixes are made available for the actively supported releases. See the
|
||||
[Policies page](https://docs.lvgl.io/master/introduction/policies) for the
|
||||
current support table.
|
||||
|
||||
## SBOM and more
|
||||
|
||||
LVGL publishes a machine-readable SBOM (SPDX 3.0.1) in the [`sbom/`](sbom/)
|
||||
folder and a human-readable component list in
|
||||
[`COPYRIGHTS.md`](COPYRIGHTS.md).
|
||||
|
||||
For our full security commitment, vulnerability handling process, and how LVGL
|
||||
supports users' EU Cyber Resilience Act (CRA) obligations, see the
|
||||
[Security page in the documentation](https://docs.lvgl.io/master/introduction/security).
|
||||
@@ -5,6 +5,7 @@
|
||||
"requirements",
|
||||
"license",
|
||||
"policies",
|
||||
"security",
|
||||
"faq"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -0,0 +1,100 @@
|
||||
---
|
||||
title: Security
|
||||
description: "LVGL's security commitment, vulnerability reporting process, SBOM, and how LVGL supports our users' EU Cyber Resilience Act (CRA) obligations"
|
||||
---
|
||||
|
||||
## Our commitment
|
||||
|
||||
LVGL is used in millions of devices, many of them shipped commercially and
|
||||
placed on regulated markets. We take the security of the library and of the
|
||||
products built on it seriously. LVGL Kft., as the legal entity stewarding the
|
||||
project, maintains a cybersecurity policy that covers:
|
||||
|
||||
- a documented **coordinated vulnerability disclosure** process,
|
||||
- a published, machine-readable **Software Bill of Materials (SBOM)**,
|
||||
- vulnerability handling with public security advisories, and
|
||||
- cooperation with users, integrators, and the relevant authorities.
|
||||
|
||||
This page describes those processes and how they help you meet your own
|
||||
obligations under regulations such as the EU Cyber Resilience Act (CRA).
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
**Please do not open a public GitHub issue for security problems.**
|
||||
|
||||
Report suspected vulnerabilities privately by email to
|
||||
[security@lvgl.io](mailto:security@lvgl.io).
|
||||
|
||||
Please include, as far as you can:
|
||||
|
||||
- the affected version(s) and configuration (`lv_conf.h` toggles, target),
|
||||
- a description of the impact,
|
||||
- steps to reproduce or a proof of concept, and
|
||||
- any suggested fix or mitigation.
|
||||
|
||||
We support **coordinated disclosure**: we ask that you give us a reasonable
|
||||
window to release a fix before any public disclosure, and we will credit you in
|
||||
the advisory unless you prefer otherwise.
|
||||
|
||||
## How we handle reports
|
||||
|
||||
| Stage | What happens |
|
||||
| --- | --- |
|
||||
| Acknowledge | We confirm receipt of your report, typically within a few business days. |
|
||||
| Triage | We reproduce and assess severity, and determine the affected versions. |
|
||||
| Fix | We develop and review a fix on a private track when needed. |
|
||||
| Advisory | We publish a [GitHub Security Advisory](https://github.com/lvgl/lvgl/security/advisories) and, where applicable, request a CVE identifier. |
|
||||
| Release | The fix ships in a patch release; see [Policies](/introduction/policies) for the supported versions. |
|
||||
|
||||
Fixes are made available for the actively supported releases listed on the
|
||||
[Policies](/introduction/policies) page.
|
||||
|
||||
## Software Bill of Materials (SBOM)
|
||||
|
||||
LVGL publishes two views of its component inventory:
|
||||
|
||||
- [**`sbom/lvgl.spdx.json`**](https://github.com/lvgl/lvgl/blob/master/sbom/lvgl.spdx.json): the **machine-readable** SBOM, in the
|
||||
[SPDX 3.0.1](https://spdx.github.io/spdx-spec/v3.0.1/) JSON-LD format, a
|
||||
commonly used standard suitable for automated tooling.
|
||||
- [**`COPYRIGHTS.md`**](https://github.com/lvgl/lvgl/blob/master/COPYRIGHTS.md): the **human-readable** list of every third-party component with its license
|
||||
and copyright.
|
||||
|
||||
Both are generated from a single source of truth,
|
||||
[`sbom/third_party.json`](https://github.com/lvgl/lvgl/blob/master/sbom/third_party.json),
|
||||
and their correctness is enforced by CI, so they always track the checked-out
|
||||
version.
|
||||
|
||||
See the [SBOM README](https://github.com/lvgl/lvgl/blob/master/sbom/README.md)
|
||||
for the file layout, how to regenerate the artifacts, and how to validate them.
|
||||
|
||||
Note that some optional dependencies (for example FreeType) are **provided by
|
||||
the integrator** rather than bundled with LVGL; the SBOM lists LVGL's
|
||||
integration interface, but you are responsible for the SBOM entries of the
|
||||
components you supply yourself.
|
||||
|
||||
## LVGL and the EU Cyber Resilience Act (CRA)
|
||||
|
||||
The CRA (Regulation (EU) 2024/2847) places obligations on **manufacturers**
|
||||
who place *products with digital elements* on the EU market. LVGL is a free and
|
||||
open-source **software component**, not a finished product placed on the market
|
||||
by LVGL Kft. The CRA obligations for a shipped product therefore fall on the
|
||||
**manufacturer that integrates LVGL** into that product.
|
||||
|
||||
What LVGL provides is the upstream foundation that makes meeting those
|
||||
obligations easier:
|
||||
|
||||
- a **machine-readable SBOM** covering LVGL and its bundled third-party
|
||||
components,
|
||||
- a **coordinated vulnerability disclosure** process and public security
|
||||
advisories, and
|
||||
- clear licensing and component provenance in `COPYRIGHTS.md`.
|
||||
|
||||
As the open-source steward of the project, LVGL Kft. maintains the cybersecurity
|
||||
policy described on this page and cooperates with users and authorities on
|
||||
vulnerability handling.
|
||||
|
||||
> **Not legal advice.** This page describes LVGL's processes and artifacts. It
|
||||
> is not legal advice, and it does not by itself make any product compliant. The
|
||||
> precise classification of your product and of LVGL Kft. under the CRA, and the
|
||||
> steps required for your conformity, should be confirmed with qualified
|
||||
> counsel. For questions, contact [lvgl@lvgl.io](mailto:lvgl@lvgl.io).
|
||||
@@ -0,0 +1,86 @@
|
||||
# LVGL SBOM
|
||||
|
||||
This folder contains the Software Bill of Materials (SBOM) for LVGL in
|
||||
[SPDX 3.0.1](https://spdx.github.io/spdx-spec/v3.0.1/) JSON-LD format, plus the
|
||||
single source of truth it is generated from.
|
||||
|
||||
## Files
|
||||
|
||||
| File | Description |
|
||||
|------|-------------|
|
||||
| `third_party.json` | **Single source of truth** — every third-party dependency, its license, supplier and source |
|
||||
| `lvgl.spdx.json` | Generated SPDX 3.0.1 SBOM |
|
||||
| `requirements.txt` | Pinned tooling for validation / the CI gate |
|
||||
| `README.md` | This file |
|
||||
|
||||
Two artifacts are **generated** from `third_party.json` — do not edit them by hand:
|
||||
|
||||
- `sbom/lvgl.spdx.json` (this folder)
|
||||
- `COPYRIGHTS.md` (repo root)
|
||||
|
||||
## Regenerating
|
||||
|
||||
When a dependency is added, removed, or relicensed, edit
|
||||
`sbom/third_party.json` and regenerate both outputs:
|
||||
|
||||
```sh
|
||||
python3 scripts/generate_copyrights.py # -> COPYRIGHTS.md
|
||||
python3 scripts/generate_sbom.py # -> sbom/lvgl.spdx.json
|
||||
```
|
||||
|
||||
The LVGL version is read from `include/lvgl/lv_version.h` and recorded inside
|
||||
the document, so the package version always tracks the checked-out tree. The
|
||||
file name itself is unversioned — the SBOM is bundled inside a given LVGL
|
||||
version anyway.
|
||||
|
||||
## Validating
|
||||
|
||||
The SBOM is validated against the **official SPDX 3.0.1 JSON Schema** (SPDX's
|
||||
own recommended method) using
|
||||
[check-jsonschema](https://github.com/python-jsonschema/check-jsonschema):
|
||||
|
||||
```sh
|
||||
python3 -m pip install -r sbom/requirements.txt
|
||||
python3 scripts/validate_sbom.py
|
||||
```
|
||||
|
||||
## CI
|
||||
|
||||
The `Static Checks` workflow (`.github/workflows/static_checks.yml`) fails the
|
||||
build if any generated file drifts from `sbom/third_party.json` or the SBOM is
|
||||
not schema-valid:
|
||||
|
||||
- `generate_copyrights.py --check` — COPYRIGHTS.md is up to date
|
||||
- `generate_sbom.py --check` — SBOM is up to date (ignores the creation timestamp)
|
||||
- `validate_sbom.py` — SBOM validates against the SPDX JSON Schema
|
||||
|
||||
## `third_party.json` fields
|
||||
|
||||
Each entry in `components`:
|
||||
|
||||
| field | used by | notes |
|
||||
|---------------|--------------------|-------|
|
||||
| `key` | SBOM | slug for SPDX element ids |
|
||||
| `name` | SBOM + COPYRIGHTS | component title |
|
||||
| `paths` | SBOM + COPYRIGHTS | in-tree locations |
|
||||
| `sources` | SBOM + COPYRIGHTS | `[{url, note?}]`; array because e.g. TinyTTF has two upstreams. First url is the SPDX download location |
|
||||
| `note` | SBOM + COPYRIGHTS | free-form note |
|
||||
| `version` | SBOM | vendored snapshot version (from an in-tree version macro/string), or `NOASSERTION` when the upstream copy carries no version |
|
||||
| `license` | SBOM | SPDX license expression (or `LicenseRef-*`) |
|
||||
| `license_file`| SBOM | path to embed for a custom `LicenseRef-*` license |
|
||||
| `copyright` | SBOM | upstream copyright statement (from the library's LICENSE/source header) |
|
||||
| `supplier` | SBOM | `{name, type}` where type is `person` or `organization` |
|
||||
| `purl` | SBOM | Package URL identifier |
|
||||
| `purpose` | SBOM | SPDX `software_primaryPurpose` |
|
||||
| `third_party` | SBOM | `false` marks LVGL's own code — omitted from the SBOM component list (COPYRIGHTS.md renders every entry) |
|
||||
|
||||
## Notes on the data
|
||||
|
||||
- The inventory was curated from `COPYRIGHTS.md`, the `LV_USE_*` toggles in
|
||||
`lv_conf_template.h`, and the `src/libs/**/LICENSE*` files.
|
||||
- **FreeType** is listed because LVGL ships its integration interface, but
|
||||
FreeType itself is not part of LVGL and must be provided by the integrator.
|
||||
- In SPDX 3.0 a package has no license field; licensing is expressed as
|
||||
`Relationship` elements (`from` package → `hasDeclaredLicense` /
|
||||
`hasConcludedLicense` → `to` license expression). This is why the SBOM
|
||||
contains `Relationship` nodes.
|
||||
+1271
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,4 @@
|
||||
# Tooling for the SBOM compliance gate (see .github/workflows/code_generation.yml).
|
||||
# The validator version is pinned so the gate does not change or break from an
|
||||
# unreviewed upstream release; bump it here deliberately when updating.
|
||||
check-jsonschema==0.37.4
|
||||
File diff suppressed because it is too large
Load Diff
Executable
+94
@@ -0,0 +1,94 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Regenerate COPYRIGHTS.md from the single source of truth.
|
||||
|
||||
Component data lives in sbom/third_party.json, which is also used to
|
||||
generate the SPDX SBOM (see generate_sbom.py). Edit that JSON, then run this
|
||||
script to refresh COPYRIGHTS.md.
|
||||
|
||||
Usage:
|
||||
python3 scripts/generate_copyrights.py [--output COPYRIGHTS.md] [--check]
|
||||
|
||||
--check exit non-zero if COPYRIGHTS.md is out of date (for CI).
|
||||
"""
|
||||
|
||||
import argparse
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
|
||||
REPO_ROOT = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
DATA_FILE = os.path.join(REPO_ROOT, "sbom", "third_party.json")
|
||||
|
||||
HEADER = (
|
||||
"LVGL uses the following third-party libraries.\n"
|
||||
"Each entry lists its SPDX license expression below. The full license text "
|
||||
"is, for most libraries, found in the corresponding library folder (see the "
|
||||
"paths); some libraries only reference their license rather than shipping "
|
||||
"the full text. A machine-readable inventory is available in `sbom/`.\n"
|
||||
)
|
||||
|
||||
|
||||
def render(data):
|
||||
lines = [HEADER]
|
||||
for comp in data["components"]:
|
||||
lines.append("**%s**" % comp["name"])
|
||||
|
||||
paths = comp.get("paths", [])
|
||||
if len(paths) == 1:
|
||||
lines.append("- Path: %s" % paths[0])
|
||||
elif paths:
|
||||
lines.append("- Path:")
|
||||
for p in paths:
|
||||
lines.append(" - %s" % p)
|
||||
|
||||
sources = comp.get("sources", [])
|
||||
if len(sources) == 1 and not sources[0].get("note"):
|
||||
lines.append("- Source: %s" % sources[0]["url"])
|
||||
elif sources:
|
||||
lines.append("- Source:")
|
||||
for s in sources:
|
||||
suffix = " (*%s*)" % s["note"] if s.get("note") else ""
|
||||
lines.append(" - %s%s" % (s["url"], suffix))
|
||||
|
||||
if comp.get("license"):
|
||||
lines.append("- License: %s" % comp["license"])
|
||||
|
||||
if comp.get("note"):
|
||||
lines.append("- Note: %s" % comp["note"])
|
||||
|
||||
lines.append("") # blank line between entries
|
||||
|
||||
return "\n".join(lines).rstrip() + "\n"
|
||||
|
||||
|
||||
def main():
|
||||
parser = argparse.ArgumentParser(description="Regenerate COPYRIGHTS.md.")
|
||||
parser.add_argument("--output", default=os.path.join(REPO_ROOT, "COPYRIGHTS.md"),
|
||||
help="Output file (default: COPYRIGHTS.md).")
|
||||
parser.add_argument("--check", action="store_true",
|
||||
help="Exit non-zero if the output is out of date.")
|
||||
args = parser.parse_args()
|
||||
|
||||
with open(DATA_FILE, encoding="utf-8") as fh:
|
||||
data = json.load(fh)
|
||||
content = render(data)
|
||||
|
||||
if args.check:
|
||||
current = ""
|
||||
if os.path.isfile(args.output):
|
||||
with open(args.output, encoding="utf-8") as fh:
|
||||
current = fh.read()
|
||||
if current != content:
|
||||
print("%s is out of date; run scripts/generate_copyrights.py" % args.output)
|
||||
return 1
|
||||
print("%s is up to date" % args.output)
|
||||
return 0
|
||||
|
||||
with open(args.output, "w", encoding="utf-8") as fh:
|
||||
fh.write(content)
|
||||
print("Wrote %s (%d components)" % (args.output, len(data["components"])))
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+392
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,67 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Validate LVGL's SPDX 3.0 SBOM against the official SPDX JSON Schema.
|
||||
|
||||
This is the validation method recommended by SPDX itself: check the document
|
||||
against the published JSON Schema for its spec version. It uses check-jsonschema
|
||||
(https://github.com/python-jsonschema/check-jsonschema) as the engine:
|
||||
|
||||
python3 -m pip install check-jsonschema
|
||||
|
||||
Usage:
|
||||
python3 scripts/validate_sbom.py [SBOM ...]
|
||||
[--schema URL_OR_PATH] [--spec-version 3.0.1]
|
||||
|
||||
With no SBOM argument sbom/lvgl.spdx.json is validated. The schema
|
||||
defaults to the official SPDX schema for --spec-version; pass a local path with
|
||||
--schema to validate offline.
|
||||
"""
|
||||
|
||||
import argparse
|
||||
import glob
|
||||
import importlib.util
|
||||
import os
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
REPO_ROOT = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
SBOM_DIR = os.path.join(REPO_ROOT, "sbom")
|
||||
SCHEMA_URL = "https://spdx.org/schema/%s/spdx-json-schema.json"
|
||||
|
||||
|
||||
def main():
|
||||
parser = argparse.ArgumentParser(
|
||||
description="Validate LVGL's SPDX SBOM against the official SPDX JSON Schema.")
|
||||
parser.add_argument("sboms", nargs="*",
|
||||
help="SBOM file(s) to validate (default: sbom/lvgl.spdx.json).")
|
||||
parser.add_argument("--spec-version", default="3.0.1",
|
||||
help="SPDX spec version whose schema to use (default: 3.0.1).")
|
||||
parser.add_argument("--schema", default=None,
|
||||
help="Override the schema URL or local file path.")
|
||||
args = parser.parse_args()
|
||||
|
||||
sboms = args.sboms or sorted(glob.glob(os.path.join(SBOM_DIR, "lvgl.spdx.json")))
|
||||
if not sboms:
|
||||
print("No SBOM files found in %s (run scripts/generate_sbom.py first)." % SBOM_DIR)
|
||||
return 1
|
||||
missing = [p for p in sboms if not os.path.isfile(p)]
|
||||
if missing:
|
||||
print("SBOM file(s) not found: %s" % ", ".join(missing))
|
||||
return 1
|
||||
|
||||
# Launching `python -m check_jsonschema` when the module is absent exits
|
||||
# with the interpreter's own error code (not FileNotFoundError), so detect
|
||||
# the module up front to surface the documented install instructions.
|
||||
if importlib.util.find_spec("check_jsonschema") is None:
|
||||
print("check-jsonschema is not installed. Install it with:\n"
|
||||
" python3 -m pip install check-jsonschema")
|
||||
return 2
|
||||
|
||||
schema = args.schema or (SCHEMA_URL % args.spec_version)
|
||||
|
||||
cmd = [sys.executable, "-m", "check_jsonschema", "--schemafile", schema] + sboms
|
||||
print("Validating against SPDX %s schema:\n %s\n" % (args.spec_version, schema))
|
||||
return subprocess.run(cmd).returncode
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Reference in New Issue
Block a user