|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
It would be 7:30pm PST
Does this work?
-miki
--
Miki Demeter (she/her/Miki)
Security Researcher / FW Developer
FST
Intel Corporation
Co-Chair, Network of Intel African-Ancestry(NIA) -
It would be 7:30pm PST
Does this work?
-miki
--
Miki Demeter (she/her/Miki)
Security Researcher / FW Developer
FST
Intel Corporation
Co-Chair, Network of Intel African-Ancestry(NIA) -
|
By
Demeter, Miki
·
#774
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
Yes, we can run other analyzer; however, in case of CodeChecker we also need a server to upload the result to.
Yes, we can run other analyzer; however, in case of CodeChecker we also need a server to upload the result to.
|
By
Felix Polyudov
·
#773
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
I have Coverity scan builds running in a GitHub Action and then uploaded to Coverity.
We should be able to configure a GitHub Action to run other analyzers.
Mike
I have Coverity scan builds running in a GitHub Action and then uploaded to Coverity.
We should be able to configure a GitHub Action to run other analyzers.
Mike
|
By
Michael D Kinney
·
#772
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
(Re-adding devel@ since Felix dropped it)
wrote:
--
Pedro Falcato
(Re-adding devel@ since Felix dropped it)
wrote:
--
Pedro Falcato
|
By
Pedro Falcato
·
#771
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
Just want to note that if we want to go ahead with fuzzing (I detailed a
possible plan to do so in the mailing list a month or so ago) we will
definitely need somewhere to run fuzzing (even if it's
Just want to note that if we want to go ahead with fuzzing (I detailed a
possible plan to do so in the mailing list a month or so ago) we will
definitely need somewhere to run fuzzing (even if it's
|
By
Pedro Falcato
·
#770
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
Yes, LLVM/CLANG Static Analyzer is another possibility. I've mentioned it in the first version of the RFC.
CodeChecker (https://codechecker.readthedocs.io/en/latest/) is an open source front-end for
Yes, LLVM/CLANG Static Analyzer is another possibility. I've mentioned it in the first version of the RFC.
CodeChecker (https://codechecker.readthedocs.io/en/latest/) is an open source front-end for
|
By
Felix Polyudov
·
#769
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
LLVM's tools also appear to be much easier to review, for other people to run etc. I'd suggest at least starting with clang-tidy + scan-build and possibly adding Coverity later.
I've found the
LLVM's tools also appear to be much easier to review, for other people to run etc. I'd suggest at least starting with clang-tidy + scan-build and possibly adding Coverity later.
I've found the
|
By
Rebecca Cran
·
#768
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
(Replying under Mike for devel visibility)
Felix,
Why coverity? I feel like we could run something akin to LLVM's clang-tidy
+ scan-build; it's open source (transparent *and* we can improve it or
(Replying under Mike for devel visibility)
Felix,
Why coverity? I feel like we could run something akin to LLVM's clang-tidy
+ scan-build; it's open source (transparent *and* we can improve it or
|
By
Pedro Falcato
·
#767
·
|
|
Re: RFC v2: Static Analysis in edk2 CI
+devel@edk2.groups.io
Mike
+devel@edk2.groups.io
Mike
|
By
Michael D Kinney
·
#766
·
|
|
RFC v2: Static Analysis in edk2 CI
This is version 2 of the proposal that provides additional details regarding the bring up process.
The initial version is at https://edk2.groups.io/g/rfc/message/696
The goal of the proposal is
This is version 2 of the proposal that provides additional details regarding the bring up process.
The initial version is at https://edk2.groups.io/g/rfc/message/696
The goal of the proposal is
|
By
Felix Polyudov
·
#765
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
Nice, didn't know about those flags. I'll take a closer look at those
and see if any other flag could be useful.
One of the challenges of this patch was to check that the edition
calculation was
Nice, didn't know about those flags. I'll take a closer look at those
and see if any other flag could be useful.
One of the challenges of this patch was to check that the edition
calculation was
|
By
Martin Fernandez
·
#764
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
Yep, I'm good with the latter.
Yep, I'm good with the latter.
|
By
Martin Fernandez <martin.fernandez@...>
·
#763
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
Definitely the latter please! Martin, is that okay for you?
Yes; I'll do a big picture overview, an introduction into uswid and
Martin can explain the patch functionality in more detail. Does
Definitely the latter please! Martin, is that okay for you?
Yes; I'll do a big picture overview, an introduction into uswid and
Martin can explain the patch functionality in more detail. Does
|
By
Richard Hughes <hughsient@...>
·
#762
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
Hi Miki,
Sure, not a problem. Let me know what you'd like me to present, and a
rough duration to stick to. I did a similar thing for the coreboot
leadership so it's no problem at all.
Richard
Hi Miki,
Sure, not a problem. Let me know what you'd like me to present, and a
rough duration to stick to. I did a similar thing for the coreboot
leadership so it's no problem at all.
Richard
|
By
Richard Hughes <hughsient@...>
·
#761
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
I am also interested in this capability.
There are (undocumented?) capabilities in the build scripts currently that may be germane. --hash, --binary-destination, --binary-source.
The rough usage
I am also interested in this capability.
There are (undocumented?) capabilities in the build scripts currently that may be germane. --hash, --binary-destination, --binary-source.
The rough usage
|
By
Isaac Oram
·
#760
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
Martin, Richard
Thank you I will add you to the agenda for the July 7th meeting at 7:30 pm
-miki
--
Miki Demeter (she/her/Miki)
Security Researcher / FW Developer
FST
Intel Corporation
Co-Chair,
Martin, Richard
Thank you I will add you to the agenda for the July 7th meeting at 7:30 pm
-miki
--
Miki Demeter (she/her/Miki)
Security Researcher / FW Developer
FST
Intel Corporation
Co-Chair,
|
By
Demeter, Miki
·
#759
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
Great.
Next community meeting is July 7th.
Is morning or evening best for you? i.e. 7am or 7:30pm
Is 20minutes enough time?
-miki
--
Miki Demeter (she/her/Miki)
Security Researcher / FW
Great.
Next community meeting is July 7th.
Is morning or evening best for you? i.e. 7am or 7:30pm
Is 20minutes enough time?
-miki
--
Miki Demeter (she/her/Miki)
Security Researcher / FW
|
By
Demeter, Miki
·
#758
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
Hi Richard,
Would you like to attend one of the community meetings coming up and talk about this patch.
-miki (Community manager Intel)
Hi Richard,
Would you like to attend one of the community meetings coming up and talk about this patch.
-miki (Community manager Intel)
|
By
Demeter, Miki
·
#757
·
|
|
Re: [PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
<martin.fernandez@...> wrote:
If it helps drive progress, both AMI and Insyde have been testing
building images based on this patch. I'd really like something like
this to be included in
<martin.fernandez@...> wrote:
If it helps drive progress, both AMI and Insyde have been testing
building images based on this patch. I'd really like something like
this to be included in
|
By
Richard Hughes <hughsient@...>
·
#756
·
|
|
[PATCH] [rfc] Add SBOM (software bill of materials) to the efi binaries
This patch modifies the build system in order to generate and use
metadata to add it to the efi binaries. It uses python-uswid [1],
given a set of config files (.ini) with the metadata it
This patch modifies the build system in order to generate and use
metadata to add it to the efi binaries. It uses python-uswid [1],
given a set of config files (.ini) with the metadata it
|
By
Martin Fernandez <martin.fernandez@...>
·
#755
·
|