supply-chain
unknown
published unknown ago
13 stars
3 forks
12 watchers
Apache License 2.0
public

Supply-chain rules for Bazel

This repository contains Bazel modules for injecting and collecting supply-chain metadata into builds.

This project is the successor to rules_license.

The intended use cases are:

  • declaring metadata about packages, such as
    • the licenses the package is available under
    • the canonical package name and version
    • copyright information
    • ... and more TBD in the future
  • gathering license declarations into artifacts to ship with code
  • applying organization specific compliance constriants against the set of packages used by a target.
  • producing SBOMs for built artifacts.

WARNING: The code here is still in active initial development and will churn a lot.

Roadmap

In flux.

Q3 2025

The immediate concern is feature parity with rules_license and providing a smooth migration path.

Background reading:

These is for learning about the problem space, and our approach to solutions. Concrete specifications will always appear in checked in code rather than documents.