Progress update: End of 2023 Q2

28 views
Skip to first unread message

Tony Aiuto

unread,
Jul 6, 2023, 10:46:33 AM7/6/23
to bazel-ssc
There was a lot of activity in the last few months.
  • rules_license 0.0.7 released
    • adds package_info
    • lots of refactoring for a cleaner split between the declarative rules and the tools to build reporting
  • Bazel at head uses 0.0.7
  • Bazel has an end-to-end path for creating its own SBOM
    • bazel build //tools/compliance:bazel_sbom
    • This relies heavily on the maven lock files from rules_jvm_external
    • There is more work to do with pickup up proper package versions and download URLs
    • We expect to incorporate creating this into the nightly builds and distributing it alongside the bazel binary
For Q3, I expect to
  • Allow for package information to come from the Bazel Central Registry
  • build paths to incorporate package metadata from other repository systems (such as pypi)
  • Improve the examples
Reply all
Reply to author
Forward
0 new messages