From 9a5cf1ef3fdb244c29a4411b72ec4bb895054ad3 Mon Sep 17 00:00:00 2001 From: Charlie Le Date: Mon, 28 Sep 2026 15:49:47 -0700 Subject: [PATCH] Generate the Go modules SBOM from a clean checkout of the release tag bom includes every file under the directory it scans, including untracked and gitignored ones. Running the script from a working checkout therefore put local-only files into the published SBOM: the go-mod.spdx files for v1.22.0-rc.0 and v1.22.0-rc.1 list about 133,000 files from local .claude/worktrees directories and about 1,500 from website/node_modules, out of about 145,000 in total. Check out the release tag into a temporary worktree and scan that instead, removing the worktree on exit. Name the checkout directory "cortex", since bom names the top-level package after it. Signed-off-by: Charlie Le --- RELEASE.md | 1 + tools/generate-sbom.sh | 10 +++++++++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/RELEASE.md b/RELEASE.md index fc84ff5bce8..375a33f4db1 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -139,6 +139,7 @@ To publish a stable release: ./tools/generate-sbom.sh /path/to/cortex ``` This generates SBOMs for the Go modules and all container images (cortex, query-tee, test-exporter, thanosconvert) and packages them into `dist/sbom.tar.gz`. + The Go modules SBOM is generated from a clean checkout of the release tag, so the tag must exist in your local repository. Untracked files in your working tree are not included. 1. Download the artifacts attached to the published release ```bash curl -H "Authorization: Bearer " -s https://api.github.com/repos/cortexproject/cortex/releases/tags/ \ diff --git a/tools/generate-sbom.sh b/tools/generate-sbom.sh index 89f7d7a5b9e..79e41d99e64 100755 --- a/tools/generate-sbom.sh +++ b/tools/generate-sbom.sh @@ -5,12 +5,20 @@ REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)" RELEASE_TAG="v$(cat "${REPO_ROOT}/VERSION" | tr -d '[:space:]')" CORTEX_REPO="${1:-$REPO_ROOT}" +# Scan a clean checkout of the release tag, not the working tree: bom includes +# every file under the directory, including untracked and gitignored ones. +# The checkout directory is named "cortex" because bom names the top-level +# package after it. +WORKTREE_PARENT="$(mktemp -d)" +trap 'git -C "$CORTEX_REPO" worktree remove --force "$WORKTREE_PARENT/cortex" >/dev/null 2>&1 || true; rm -rf "$WORKTREE_PARENT"' EXIT +git -C "$CORTEX_REPO" worktree add --detach "$WORKTREE_PARENT/cortex" "$RELEASE_TAG" + mkdir -p sbom echo "Generating go-mod SBOM..." bom generate -o sbom/go-mod.spdx \ -n https://github.com/cortexproject/cortex \ - -d "$CORTEX_REPO" + -d "$WORKTREE_PARENT/cortex" echo "Generating cortex container image SBOM..." bom generate -o sbom/cortex-container-image.spdx \