mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-23 15:54:21 -09:00
82b533e3dbb0622ba05036c5069cf3f7b6bce59b
Commite8c54ffb3d("utils/generate-cyclonedx: generate vcs externalReferences for source repos") added externalReferences to the source code of packages. This unfortunately causes issues with packages (in br2-external) fetching from git using the scp-like syntax, E.G.: FOO_SITE_METHOD = git FOO_SITE = git@github.com:<project>/<repo>.git Which ends up in the SBOM as: [ { "type": "vcs", "url": "git@github.com:<project>/<repo>.git", "comment": "git repository" } ] This (correctly) causes Dependency track to reject the SBOM import with: { "status": 400, "title": "The uploaded BOM is invalid", "detail": "Schema validation failed", "errors": [ "$.components[2].externalReferences[0].url: does not match the iri-reference pattern must be a valid RFC 3987 IRI-reference", "$.components[2].externalReferences[0].url: does not match the iri-reference pattern must be a valid RFC 3987 IRI-reference", "$.components[2].externalReferences[0].url: does not match the regex pattern ^urn:cdx:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}/[1-9][0-9]*$", ] } The CycloneDX spec indeed requires a URI: The URI (URL or URN) to the external reference. External references are URIs and therefore can accept any URL scheme including https (RFC-7230), mailto (RFC-2368), tel (RFC-3966), and dns (RFC-4501) https://cyclonedx.org/docs/1.6/json/#metadata_tools_oneOf_i0_components_items_externalReferences_items_url The user@host:project/repo.git is a git-specific shorthand for a git-over-ssh URL. From man git-clone: Git supports ssh, git, http, and https protocols (in addition, ftp and ftps can be used for fetching, but this is inefficient and deprecated; do not use them). The native transport (i.e. git:// URL) does no authentication and should be used with caution on unsecured networks. The following syntaxes may be used with them: • ssh://[user@]host.xz[:port]/path/to/repo.git/ • git://host.xz[:port]/path/to/repo.git/ • http[s]://host.xz[:port]/path/to/repo.git/ • ftp[s]://host.xz[:port]/path/to/repo.git/ An alternative scp-like syntax may also be used with the ssh protocol: • [user@]host.xz:path/to/repo.git/ So convert the scp-like syntax to ssh:// URLs in parse_uris() for spec compliance. Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Acked-By: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commitebcfdb8b0a) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
…
…
Buildroot is a simple, efficient and easy-to-use tool to generate embedded Linux systems through cross-compilation. The documentation can be found in docs/manual. You can generate a text document with 'make manual-text' and read output/docs/manual/manual.text. Online documentation can be found at https://buildroot.org/docs.html To build and use the buildroot stuff, do the following: 1) run 'make menuconfig' 2) select the target architecture and the packages you wish to compile 3) run 'make' 4) wait while it compiles 5) find the kernel, bootloader, root filesystem, etc. in output/images You do not need to be root to build or run buildroot. Have fun! Buildroot comes with a basic configuration for a number of boards. Run 'make list-defconfigs' to view the list of provided configurations. Please feed suggestions, bug reports, insults, and bribes back to the buildroot mailing list: buildroot@buildroot.org You can also find us on #buildroot on OFTC IRC. If you would like to contribute patches, please read https://buildroot.org/manual.html#submitting-patches
Description
Languages
Makefile
62.6%
Python
18.8%
C
8.5%
Shell
6.1%
PHP
1.4%
Other
2.2%