Skip to content

OneCryptoPkg: SbomInserter: Update SPDX information#257

Merged
Flickdm merged 1 commit into
microsoft:mainfrom
Javagedes:personal/joeyvagedes/sbom-updates
May 15, 2026
Merged

OneCryptoPkg: SbomInserter: Update SPDX information#257
Flickdm merged 1 commit into
microsoft:mainfrom
Javagedes:personal/joeyvagedes/sbom-updates

Conversation

@Javagedes

Copy link
Copy Markdown
Collaborator

Description

  1. Standardize SPDX Ref UUID values to all lowercase
  2. Set "Creator: Organization" to "Microsoft Corporation"
  3. Add "name: OpenSSL" to the OpenSSL package portion of the SBOM

There were requests to update the top level "NAME" and package level "DownloadLocation"s, however those are currently hardcoded to NOASSERTION and cannot be changed at this time.

  • Impacts functionality?
  • Impacts security?
  • Breaking change?
  • Includes tests?
  • Includes documentation?

How This Was Tested

Viewed the generated JSON SPDX SBOM

Integration Instructions

N/A

1. Standardize SPDX Ref UUID values to all lowercase
2. Set "Creator: Organization" to "Microsoft Corporation"
3. Add "name: OpenSSL" to the OpenSSL package portion of the SBOM

There were requests to update the top level "NAME" and package level "DownloadLocation"s,
however those are currently hardcoded to NOASSERTION and cannot be changed at this time.
@Javagedes Javagedes requested review from Flickdm and apop5 May 15, 2026 15:27
@mu-automation mu-automation Bot added language:python Pull requests that update Python code impact:non-functional Does not have a functional impact labels May 15, 2026

@Flickdm Flickdm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Javagedes can you Attach a copy of the XML that this change would generate?

You can do it as a comment

@Flickdm Flickdm merged commit 6938e8e into microsoft:main May 15, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

impact:non-functional Does not have a functional impact language:python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants