Skip to content

ci(moss): (1/4) add SPDX SBOM generation and Syft setup - #5601

Open
chiajunglien wants to merge 1 commit into
mainfrom
emma/moss-pr1-sbom-syft
Open

chiajunglien wants to merge 1 commit into
mainfrom
emma/moss-pr1-sbom-syft

Conversation

@chiajunglien

@chiajunglien chiajunglien commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Description

PR 1 of 4: SBOM Generation & Syft Setup (split from #5582 per review feedback).

This PR adds SPDX 2.3 JSON SBOM generation for both the MaxText Python wheel and MaxText Docker images, and uploads Docker image SBOMs to Google Cloud Container Analysis / SCILo without changing how Docker images or PyPI packages are published:

  • Wheel SPDX SBOM Generation (.github/workflows/build_package.yml):
    • Installs curl in the python:3.12-slim-trixie container and sets up Syft using anchore/sbom-action/download-syft@v0 (e22c389904149dbc22b58101806040fa8d37a610).
    • Generates an SPDX JSON SBOM (sbom/maxtext-wheel.spdx.json) for the built maxtext wheel and uploads it as a GitHub Actions workflow artifact (maxtext-wheel-sbom).
  • Docker Image Provenance & SPDX SBOM Upload to SCILo (.github/workflows/build_and_push_docker_image.yml):
    • Enables BuildKit SLSA provenance (provenance: mode=max) and SBOM (sbom: true) attestations on docker/build-push-action.
    • Sets up Syft using anchore/sbom-action/download-syft@v0 and generates an SPDX JSON SBOM (spdx-json) for the pushed Docker image digest.
    • Uploads the SPDX SBOM reference to Container Analysis / SCILo via gcloud artifacts sbom load (using ${{ vars.SBOM_BUCKET }}) and triggers gcloud artifacts sbom export.
    • Leaves the existing Docker image push destination and tagging flow unchanged.

Tests

  • Verified Syft setup, SPDX JSON SBOM generation, gcloud artifacts sbom load (to ${SBOM_BUCKET}), and gcloud artifacts sbom export in the TPU Docker Images Pipeline GitHub Actions workflow (tpu-prod-env-multipod).
  • Confirmed SBOM_REFERENCE occurrences (user-2-3.spdx.json) are created and attached to the image digests in Container Analysis.

Checklist

Before submitting this PR, please make sure (put X in square brackets):

  • I have performed a self-review of my code. For an optional AI review, add the gemini-review label.
  • I have necessary comments in my code, particularly in hard-to-understand areas.
  • I have run end-to-end tests tests and provided workload links above if applicable.
  • I have made or will make corresponding changes to the doc if needed, including adding new documentation pages to the relevant Table of Contents (toctree directive) as explained in our documentation.

@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@chiajunglien
chiajunglien force-pushed the emma/moss-pr1-sbom-syft branch from 6000542 to a1140f1 Compare October 8, 2026 03:38
@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Signed-off-by: EmmaLien <emmalien@google.com>
@chiajunglien
chiajunglien force-pushed the emma/moss-pr1-sbom-syft branch from a1140f1 to 6af4041 Compare October 8, 2026 06:48
@chiajunglien chiajunglien changed the title ci(moss): add SPDX SBOM generation and Syft setup ci(moss): (1/4) add SPDX SBOM generation and Syft setup Oct 8, 2026
@SurbhiJainUSC

Copy link
Copy Markdown
Collaborator

@chiajunglien - please resolve merge conflicts.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants