Skip to content

Generate the Go modules SBOM from a clean checkout of the release tag - #7866

Open
CharlieTLe wants to merge 1 commit into
cortexproject:masterfrom
CharlieTLe:sbom-scan-clean-worktree
Open

CharlieTLe wants to merge 1 commit into
cortexproject:masterfrom
CharlieTLe:sbom-scan-clean-worktree

Conversation

@CharlieTLe

Copy link
Copy Markdown
Member

bom generate -d <dir> includes every file under the directory, including untracked and gitignored ones. tools/generate-sbom.sh pointed it at the working checkout, so whatever was lying around locally ended up in the published SBOM.

For v1.22.0-rc.0 and v1.22.0-rc.1, go-mod.spdx is 115 MB and lists about 145,000 files, of which about 133,000 are under local .claude/worktrees/ directories and about 1,500 under website/node_modules/. The Go dependency inventory was unaffected (231 packages either way); the file list and size were not. Nothing sensitive was included: the stray files are other copies of this repository's source.

Change

  • Check out the release tag into a temporary git worktree, scan that, and remove it on exit.
  • Name the checkout directory cortex, because bom names the top-level SPDX package after the directory. This keeps PackageName: cortex as in previous releases.
  • RELEASE.md: note that the tag must exist locally.

A clean scan of v1.22.0-rc.1 produces the same 231 packages with about 10,700 file entries (about 8.8 MB).

Testing

Ran the script with a stub bom that records the directory it was given: it scanned a worktree at the release tag, named cortex, with no untracked or ignored files and no .claude/, and the worktree was removed afterwards.

bom includes every file under the directory it scans, including untracked
and gitignored ones. Running the script from a working checkout therefore
put local-only files into the published SBOM: the go-mod.spdx files for
v1.22.0-rc.0 and v1.22.0-rc.1 list about 133,000 files from local
.claude/worktrees directories and about 1,500 from website/node_modules,
out of about 145,000 in total.

Check out the release tag into a temporary worktree and scan that instead,
removing the worktree on exit. Name the checkout directory "cortex", since
bom names the top-level package after it.

Signed-off-by: Charlie Le <charlie_le@apple.com>
@CharlieTLe
CharlieTLe requested a review from a team as a code owner September 28, 2026 22:49
@CharlieTLe
CharlieTLe requested a review from yeya24 September 28, 2026 22:49

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants