mirror of https://github.com/wolfSSL/wolfBoot.git
tools/sbom/.wolfglass-rev named 1bfcf4f1a293ba09f0ff6d67904dca09ee8eb6d7, which exists in no repository. The vendored content is wolfGlass d34a906638444b6990218a49927bcebafc5a539b: tools/wolfglass-sync --check against that revision reports every file identical and only the pin itself as drift. A bare SHA with nothing checking it is also how a 1803-line vendored generator drifts from the copy wolfSSL controls, or carries a local patch, without anything noticing. Add a job that checks wolfGlass out at the pinned revision and runs its own tools/wolfglass-sync --check, which compares every vendored file against share/ and the pin against HEAD. An unresolvable revision now fails that job rather than sitting in the tree. A fork PR has no token to read wolfGlass with, so the job reports a notice and passes there; the run on wolfSSL/wolfBoot is the gate. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> |
||
|---|---|---|
| .. | ||
| armclang | ||
| bin-assemble | ||
| check_config | ||
| ci | ||
| delta | ||
| efi | ||
| elf-parser | ||
| fdt-parser | ||
| keytools | ||
| lms | ||
| openocd | ||
| renode | ||
| sbom | ||
| scripts | ||
| squashelf | ||
| test-expect-version | ||
| test-update-server | ||
| tpm | ||
| uart-flash-server | ||
| unit-tests | ||
| xmss | ||
| config.mk | ||
| test-delta.mk | ||
| test-enc.mk | ||
| test-renode.mk | ||
| test.mk | ||
| wolfboot-rpi-devicetree.diff | ||