Uploaded image for project: 'Qt'
  1. Qt
  2. QTBUG-131377

Include Chromium in SBOM

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • P1: Critical
    • None
    • 6.8
    • Other
    • 9a3998692 (dev), 97ac40531 (dev), f086e72b7 (dev), b8f5e5f55 (dev), 8c754dcbb (dev), d079fdd76 (dev), 2fa815341 (dev), a32359a10 (6.9), a33ce2a2c (6.9), 31237ffd5 (6.9), 97775f43a (6.9), 5a878ca69 (6.9), 6e74281ba (6.9), 419979e0d (6.9), 30bfeab29 (6.8)

    Description

      Chromium is missing from the Qt 6.8 SBOM. SBOM should cover all Qt WebEngine third party components, including Chroumium. 

      This task was identified as part of the CRA compliance assessment:

      Expand SBOM structure to include all third-party components, for example Chromium in Qt Framework, to a feasible depth. The SBOM should provide the information required to identify potential known vulnerabilities in third-party components. The CRA minimum requirement is a top-level SBOM.

      Outcome

      SBOMs cover Chromium.

      Reasoning

      The CRA requires that Qt produce a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies for each product. The CRA's key purpose of the SBOM is to enable Qt to ensure that its products do not contain vulnerable components developed by third parties. It is thus of utmost importance that the SBOM covers all third-party components in the product, at the very least on a top-level.

      CRA Reference

      Section 77

      OWASP SAMM reference

      Implementation business function:
      Secure Build practice includes activities such as keeping a record of all dependencies and including at least the following information:

      • where it is used or referenced
      • version used
      • license
      • source information (link to repository, author's name, etc.)
      • support and maintenance status of the dependency.

      Attachments

        Issue Links

          For Gerrit Dashboard: QTBUG-131377
          # Subject Branch Project Status CR V

          Activity

            People

              moheim Moss Heim
              elri Ella Rinnemaa
              Petri Maanonen Petri Maanonen
              Qt WebEngine Team Qt WebEngine Team
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:

                Gerrit Reviews

                  There is 1 open Gerrit change