utils/generate-cyclonedx: generate externalReferences with source-distribution

BSI TR-03183-2 5.4.2 [1] lists source code URIs under "Additional data fields
for each component", and as such "MUST additionally be provided, if it exists".

If a http or https source download URI is available from show-info, extract
it and include it as an externalReference of type "source-distribution" in the
CycloneDX output.

[1] https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-2_v2_1_0.pdf?__blob=publicationFile&v=5

Signed-off-by: Martin Willi <martin@strongswan.org>
Acked-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
This commit is contained in:
Martin Willi
2026-04-09 10:13:58 +02:00
committed by Arnout Vandecappelle
parent cc41cc3fcd
commit e4f0fb126d
2 changed files with 73 additions and 0 deletions

View File

@@ -140,3 +140,29 @@ class TestGenerateCycloneDX(unittest.TestCase):
foo_deps = next(d for d in result["dependencies"] if d["ref"] == "package-foo")
self.assertEqual(foo_deps["dependsOn"], ["package-bar", "skeleton-baz"])
def test_external_references(self):
info = self._make_show_info()
info["package-foo"]["downloads"] = [
{
"source": "foo-1.2.tar.gz",
"uris": [
"https+https://sources.buildroot.net/foo",
"http|https+https://mirror.example.org/foo",
],
},
]
result = self._run_script(show_info=info)
foo = self._find_component(result, "package-foo")
self.assertIn("externalReferences", foo)
self.assertEqual(
foo["externalReferences"],
[
{
"type": "source-distribution",
"url": "https://mirror.example.org/foo/foo-1.2.tar.gz",
},
],
)