Generate the Go modules SBOM from a clean checkout of the release tag - #7866
Open
CharlieTLe wants to merge 1 commit into
Open
CharlieTLe wants to merge 1 commit into
CharlieTLe wants to merge 1 commit into
Conversation
bom includes every file under the directory it scans, including untracked and gitignored ones. Running the script from a working checkout therefore put local-only files into the published SBOM: the go-mod.spdx files for v1.22.0-rc.0 and v1.22.0-rc.1 list about 133,000 files from local .claude/worktrees directories and about 1,500 from website/node_modules, out of about 145,000 in total. Check out the release tag into a temporary worktree and scan that instead, removing the worktree on exit. Name the checkout directory "cortex", since bom names the top-level package after it. Signed-off-by: Charlie Le <charlie_le@apple.com>
friedrichg
approved these changes
Sep 30, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
bom generate -d <dir>includes every file under the directory, including untracked and gitignored ones.tools/generate-sbom.shpointed it at the working checkout, so whatever was lying around locally ended up in the published SBOM.For
v1.22.0-rc.0andv1.22.0-rc.1,go-mod.spdxis 115 MB and lists about 145,000 files, of which about 133,000 are under local.claude/worktrees/directories and about 1,500 underwebsite/node_modules/. The Go dependency inventory was unaffected (231 packages either way); the file list and size were not. Nothing sensitive was included: the stray files are other copies of this repository's source.Change
git worktree, scan that, and remove it on exit.cortex, becausebomnames the top-level SPDX package after the directory. This keepsPackageName: cortexas in previous releases.A clean scan of
v1.22.0-rc.1produces the same 231 packages with about 10,700 file entries (about 8.8 MB).Testing
Ran the script with a stub
bomthat records the directory it was given: it scanned a worktree at the release tag, namedcortex, with no untracked or ignored files and no.claude/, and the worktree was removed afterwards.