From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Mon, 14 Sep 2026 13:23:36 +0200 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x64me-0022gd-0o for lore@lore.pengutronix.de; Mon, 14 Sep 2026 13:23:36 +0200 Received: from [127.0.0.1] (helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1x64md-0006Dl-HB; Mon, 14 Sep 2026 13:23:35 +0200 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1x64mI-00065Y-Cv; Mon, 14 Sep 2026 13:23:14 +0200 Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=thorsis.com header.s=dkim header.b=g+SJJ743; spf=pass (mx1.white.stw.pengutronix.de: domain of ada@thorsis.com designates 217.92.40.78 as permitted sender) smtp.mailfrom=ada@thorsis.com; dmarc=pass (policy=quarantine) header.from=thorsis.com Received: from mail.thorsis.com (mail.thorsis.com [217.92.40.78]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id 4E7F3200F4A; Mon, 14 Sep 2026 13:23:14 +0200 (CEST) Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id 4D9A81487733; Mon, 14 Sep 2026 13:23:20 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thorsis.com; s=dkim; t=1789385000; h=from:subject:date:message-id:to:cc:mime-version: content-transfer-encoding:in-reply-to:references; bh=E/GFYvODRcVAhuiM534hGPlW1FtWkLe4ZW3gENHQlds=; b=g+SJJ743Q9Djs6wyM8t6wMNc1YztautHzcmAyokI/rX4ijo40CUwnlBD4J87esV/TPpB3/ NAnR7z93J33W5DphkxjFi5ZtpKAsYhYarwB03cb3Bkh3bIJTfvpLVyHX+KcmKp1KF3wQm7 sH9Jq8CEPBGrHmuIFW3AJ2SMxnbw0CRIcu4fz5iRCUPKAcjZawryuSzCzO8AtWbtUmTF6I 37+RsqVnUNGQCkkwAN6aYe6cDcfQNXs2iwxODgR04M2eb7c42mC3rYXFfu+TOEl6k4br7R 6Xik9Yx3/FD8cCt1NQVjcYW7Jy1W4BSOn+p20Uy0dJjpD5QVo4mtOR6fdasUIQ== To: ptxdist@pengutronix.de Date: Mon, 14 Sep 2026 13:23:10 +0200 Message-ID: <20260914112311.93693-3-ada@thorsis.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260914112311.93693-1-ada@thorsis.com> References: <20260914112311.93693-1-ada@thorsis.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-Rspamd-Server: mx1 X-Stat-Signature: 75fqyjqe8x6yniiwrqottoh6fht4ujdy X-Rspamd-Queue-Id: 4E7F3200F4A X-Spamd-Result: default: False [-2.50 / 15.00]; BAYES_HAM(-3.00)[99.99%]; MID_CONTAINS_FROM(1.00)[]; R_MISSING_CHARSET(0.50)[]; DMARC_POLICY_ALLOW(-0.50)[thorsis.com,quarantine]; R_SPF_ALLOW(-0.20)[+mx:c]; R_DKIM_ALLOW(-0.20)[thorsis.com:s=dkim]; MIME_GOOD(-0.10)[text/plain]; ASN(0.00)[asn:3320, ipnet:217.80.0.0/12, country:DE]; ARC_NA(0.00)[]; RCVD_TLS_ALL(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_COUNT_ONE(0.00)[1]; TO_DN_SOME(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; RECEIVED_HELO_LOCALHOST(0.00)[]; NEURAL_HAM(-0.00)[-1.000]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; FROM_EQ_ENVFROM(0.00)[]; TO_MATCH_ENVRCPT_SOME(0.00)[]; DKIM_TRACE(0.00)[thorsis.com:+] X-Rspamd-Action: no action Subject: [ptxdist] [PATCH 2/3] report: spdx_sbom: Fix externalPackageRef type in category SECURITY X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Alexander Dahl via ptxdist Reply-To: ptxdist@pengutronix.de Cc: Alexander Dahl , Ralf Glaser , Michael Olbrich Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false pyspdxtools -i image-root-tgz-spdx-sbom.json gives the following error: externalPackageRef type in category SECURITY must be one of ['cpe22Type', 'cpe23Type', 'advisory', 'fix', 'url', 'swid'], but is: http://spdx.org/rdf/references/cpe23Type Could not find any location in spec which requires that URL in the referenceType field. Link: https://spdx.github.io/spdx-spec/v2.3/package-information/#721-external-reference-field Link: https://spdx.github.io/spdx-spec/v2.3/external-repository-identifiers/#f2-security Signed-off-by: Alexander Dahl --- scripts/report/spdx_sbom.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/report/spdx_sbom.py b/scripts/report/spdx_sbom.py index f39b37487..7c4f1c6bb 100644 --- a/scripts/report/spdx_sbom.py +++ b/scripts/report/spdx_sbom.py @@ -121,7 +121,7 @@ class SpdxSbomGenerator(SbomGenerator): for cpe_id in self.create_cpe_ids(pkg): cpe = spdx.SPDXExternalReference() cpe.referenceCategory = "SECURITY" - cpe.referenceType = "http://spdx.org/rdf/references/cpe23Type" + cpe.referenceType = "cpe23Type" cpe.referenceLocator = cpe_id spdx_pkg.externalRefs.append(cpe) -- 2.47.3