Bladeren bron

sbom.rst: how to disable SPDX generation

Generating SPDX is enabled by default in poky but
it can take a lot of build time resources so document
how to disable it.

(From yocto-docs rev: bcd58b7a9455fbb0ea5944089d663e327f0eb38f)

Signed-off-by: Mikko Rapeli <mikko.rapeli@linaro.org>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Mikko Rapeli 2 maanden geleden
bovenliggende
commit
dd3507f6d3
1 gewijzigde bestanden met toevoegingen van 11 en 3 verwijderingen
  1. 11 3
      documentation/dev-manual/sbom.rst

+ 11 - 3
documentation/dev-manual/sbom.rst

@@ -24,12 +24,20 @@ users can read in standardized format.
 :term:`SBOM` information is also critical to performing vulnerability exposure
 assessments, as all the components used in the Software Supply Chain are listed.
 
-The OpenEmbedded build system doesn't generate such information by default.
-To make this happen, you must inherit the
-:ref:`ref-classes-create-spdx` class from a configuration file::
+The OpenEmbedded build system doesn't generate such information by default,
+though the `:term:`Poky` reference distribution has it enabled out of the box.
+
+To enable it, inherit the :ref:`ref-classes-create-spdx` class from a
+configuration file::
 
    INHERIT += "create-spdx"
 
+In the `:term:`Poky` reference distribution, :term:`SPDX` generation does
+consume some build time resources and thus if needed it can be disabled from a
+:term:`configuration file`::
+
+   INHERIT:remove = "create-spdx"
+
 Upon building an image, you will then get:
 
 -  :term:`SPDX` output in JSON format as an ``IMAGE-MACHINE.spdx.json`` file in