Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions docs/reference/files.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,38 @@ The following example shows `graph.json` file for the top-level dependency `whee
}
```

## Wheel SBOMs

When SBOM generation is enabled, Fromager writes the canonical SPDX 2.3
document to `.dist-info/sboms/fromager.spdx.json`. During source builds,
CycloneDX SBOMs generated by Maturin are read from the same directory and
their components are merged into the canonical SPDX document. Each imported
component is related to the wheel with `CONTAINS`; the CycloneDX dependency
graph is not copied. Nested target components are included, while components
with CycloneDX scope `excluded` are omitted because they are not shipped
runtime dependencies. Local `file://` download qualifiers are removed from
imported PURLs because those paths are only meaningful in the build
environment.

A CycloneDX root with a PyPI PURL matching the wheel's normalized name and
version is associated with the wheel package, so auditwheel components are not
attached to the upstream source. The original CycloneDX files are preserved.

Maturin must be version 1.12.0 or newer and must be built with its `sbom`
feature enabled. Fromager does not enable that Maturin feature automatically.
For example, a packaging environment can pass Maturin's
`MATURIN_SETUP_ARGS` with a feature set that includes `sbom`. The exact
feature set depends on the platform and packaging environment.

This merge is applied to wheels processed by Fromager's source-build path.
Downloaded prebuilt wheels retain any native SBOM files, but are not guaranteed
to receive a merged Fromager SPDX document until they go through a separate
post-download processing path.

```{versionchanged} 0.96.0
Maturin CycloneDX SBOMs are merged into the canonical Fromager SPDX SBOM.
```

## Output Directories

During the wheel building process, fromager generates multiple output directories namely `sdists-repo`, `wheels-repo` and `work-dir`. These directories contain important information related to the wheel build.
Expand Down
Loading
Loading