Uploaded image for project: 'Qt'
  1. Qt
  2. QTBUG-129602

Annotate all qt_attribution.json files with CPE and PURL values

    XMLWordPrintable

Details

    • Task
    • Resolution: Unresolved
    • P2: Important
    • None
    • None
    • None
    • fb1fd94eb (6.9), 2d6f06df6 (6.9), 83d570790 (tqtc/lts-6.8), 8e1a2810e (tqtc/lts-6.8), 116d73f76 (tqtc/lts-6.8), 92f476c66 (tqtc/lts-6.8), eb5d6e6c3 (tqtc/lts-6.8), 3fe5821da (master), 41d599f81 (dev), dc3c1708c (6.9), d2797e5fd (tqtc/lts-6.8)

    Description

      All our 3rd party sources have (or should have) an accompanying qt_attribution.json file.

      To more easily track our 3rd party supply chain, we should add relevant CPE and PURL values to the qt_attribution.json files in all our repositories.

      What CPE and PURL means can be found at https://wiki.qt.io/SBOM#CPE_and_PURL_values_in_qt_attribution.json_files

      qtbase is handled via https://codereview.qt-project.org/c/qt/qtbase/+/578553

      We need to the same for the following repos:

      • qt3d attribution reference
      • qt5compat attribution reference
      • qtapplicationmanager attribution reference
      • qtconnectivity attribution reference
      • qtdeclarative attribution reference
      • qtgrpc attribution reference
      • qtimageformats attribution reference
      • qtinterfaceframework attribution reference
      • qtmultimedia attribution reference
      • qtopcua attribution reference
      • qtpositioning attribution reference
      • qtquick3d attribution reference
      • qtsensors attribution reference
      • qtshadertools attribution reference
      • qtsvg attribution reference
      • qttools attribution reference
      • qtvehicleservices attribution reference
      • qtvirtualkeyboard attribution reference
      • qtwayland attribution reference

      Attachments

        Issue Links

          For Gerrit Dashboard: QTBUG-129602
          # Subject Branch Project Status CR V

          Activity

            People

              qtbuildsystem Qt Build System Team
              alexandru.croitor Alexandru Croitor
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:

                Gerrit Reviews

                  There are 10 open Gerrit changes