cra-kit: address Atwood re-review blockers on #574

- Replace fabricated library-binary SHA-256/SHA-1 with all-zeros sentinels
  in the pinned wolfssl-component samples (cdx/spdx + commercial variants);
  a non-reproducible binary hash must not ship in a copyable sample.
- Recompute product bom-link checksums (CycloneDX bom hash + SPDX
  externalDocumentRef) to match the edited component SBOMs.
- Give the SPDX tag-value document a distinct documentNamespace so it no
  longer collides with the JSON serialization (SPDX 2.3 sec 3.5).
- Add licenses (GPL-3.0-only) to the wolfssl component in the product CDX
  (NTIA minimum elements).
- Align conformity-assessment-route.md wording to Annex III "important" /
  Annex IV "critical", dropping the "class II" label.
- Document the sentinel digest in SAMPLE-PROVENANCE.md.

validate.sh passes (cross-document checksums + pyspdxtools schema).

Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
pull/574/head
Sameeh Jubran 2026-07-02 17:50:01 +03:00
parent 924c3d228b
commit 811b31a363
9 changed files with 32 additions and 17 deletions

View File

@ -27,6 +27,13 @@
}, },
"purl": "pkg:github/wolfSSL/wolfssl@v5.9.1", "purl": "pkg:github/wolfSSL/wolfssl@v5.9.1",
"cpe": "cpe:2.3:a:wolfssl:wolfssl:5.9.1:*:*:*:*:*:*:*", "cpe": "cpe:2.3:a:wolfssl:wolfssl:5.9.1:*:*:*:*:*:*:*",
"licenses": [
{
"license": {
"id": "GPL-3.0-only"
}
}
],
"externalReferences": [ "externalReferences": [
{ {
"type": "bom", "type": "bom",
@ -35,7 +42,7 @@
"hashes": [ "hashes": [
{ {
"alg": "SHA-256", "alg": "SHA-256",
"content": "bc8c6b9f5fbe829edb594dc74bcb95a202ca1b402ab1dca60f858aa9fe2ec6e3" "content": "f9498cc976e97dd6bd096943c6357a561f2c41a7b3c674e83a3cc47f1a3ab096"
} }
] ]
} }

View File

@ -16,7 +16,7 @@
"spdxDocument": "file:./wolfssl-component/wolfssl-5.9.1.spdx.json", "spdxDocument": "file:./wolfssl-component/wolfssl-5.9.1.spdx.json",
"checksum": { "checksum": {
"algorithm": "SHA256", "algorithm": "SHA256",
"checksumValue": "a60bda42e4e0c874f21abaed7b34e72ac6ea329662fbac33f8487608753042f2" "checksumValue": "793e78273ef4733d1dd334bac7759b1bb066e608562bc2737205c9cd4d9a56bd"
} }
} }
], ],

View File

@ -7,8 +7,16 @@ were produced with the **autotools** path:
cd "$WOLFSSL_DIR" && ./configure && make sbom cd "$WOLFSSL_DIR" && ./configure && make sbom
``` ```
They reflect a **configured library build** (SHA-256 of `libwolfssl` and full They reflect a **configured library build** — the full `wolfssl:build:*`
`wolfssl:build:*` properties from `options.h`). properties are captured from `options.h`.
The binary artifact digest (the library `PackageChecksum` / component hash and
the `libwolfssl.44.dylib` file entry) is intentionally an **all-zeros
sentinel**, not a captured hash. A compiled binary is not bit-reproducible
across toolchains, platforms, and timestamps, so a pinned sample must not ship
a concrete, real-looking binary hash that a customer might copy verbatim.
Running `./scripts/refresh-samples.sh` against your own build replaces the
sentinel with the real digest of the artifact you actually shipped.
They are **not** the same as the **embedded** demo under They are **not** the same as the **embedded** demo under
[`../wolfssl-component-embedded/`](../wolfssl-component-embedded/), which uses [`../wolfssl-component-embedded/`](../wolfssl-component-embedded/), which uses

View File

@ -37,7 +37,7 @@
"hashes": [ "hashes": [
{ {
"alg": "SHA-256", "alg": "SHA-256",
"content": "391e86477f5eee025e677a24b13e2d9a4d3e4c18d88e6359853ebf1c9932279e" "content": "0000000000000000000000000000000000000000000000000000000000000000"
} }
], ],
"externalReferences": [ "externalReferences": [
@ -315,11 +315,11 @@
"hashes": [ "hashes": [
{ {
"alg": "SHA-1", "alg": "SHA-1",
"content": "def1d74ce45e708d8230084cdea4f45a9cad144c" "content": "0000000000000000000000000000000000000000"
}, },
{ {
"alg": "SHA-256", "alg": "SHA-256",
"content": "391e86477f5eee025e677a24b13e2d9a4d3e4c18d88e6359853ebf1c9932279e" "content": "0000000000000000000000000000000000000000000000000000000000000000"
} }
] ]
} }

View File

@ -37,7 +37,7 @@
"hashes": [ "hashes": [
{ {
"alg": "SHA-256", "alg": "SHA-256",
"content": "391e86477f5eee025e677a24b13e2d9a4d3e4c18d88e6359853ebf1c9932279e" "content": "0000000000000000000000000000000000000000000000000000000000000000"
} }
], ],
"externalReferences": [ "externalReferences": [
@ -319,11 +319,11 @@
"hashes": [ "hashes": [
{ {
"alg": "SHA-1", "alg": "SHA-1",
"content": "def1d74ce45e708d8230084cdea4f45a9cad144c" "content": "0000000000000000000000000000000000000000"
}, },
{ {
"alg": "SHA-256", "alg": "SHA-256",
"content": "391e86477f5eee025e677a24b13e2d9a4d3e4c18d88e6359853ebf1c9932279e" "content": "0000000000000000000000000000000000000000000000000000000000000000"
} }
] ]
} }

View File

@ -22,7 +22,7 @@
"checksums": [ "checksums": [
{ {
"algorithm": "SHA256", "algorithm": "SHA256",
"checksumValue": "391e86477f5eee025e677a24b13e2d9a4d3e4c18d88e6359853ebf1c9932279e" "checksumValue": "0000000000000000000000000000000000000000000000000000000000000000"
} }
], ],
"licenseConcluded": "LicenseRef-wolfSSL-Commercial", "licenseConcluded": "LicenseRef-wolfSSL-Commercial",

View File

@ -3,7 +3,7 @@ SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0 DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT SPDXID: SPDXRef-DOCUMENT
DocumentName: wolfssl-5.9.1 DocumentName: wolfssl-5.9.1
DocumentNamespace: urn:uuid:480ff203-f994-5b71-b858-0653e74e422a DocumentNamespace: urn:uuid:5b1f8e0a-3c4d-5a6b-9c2e-7d1af9c02e5b
## Creation Information ## Creation Information
Creator: Organization: wolfSSL Inc. Creator: Organization: wolfSSL Inc.
@ -17,7 +17,7 @@ PackageVersion: 5.9.1
PackageSupplier: Organization: wolfSSL Inc. PackageSupplier: Organization: wolfSSL Inc.
PackageDownloadLocation: https://github.com/wolfSSL/wolfssl PackageDownloadLocation: https://github.com/wolfSSL/wolfssl
FilesAnalyzed: false FilesAnalyzed: false
PackageChecksum: SHA256: 391e86477f5eee025e677a24b13e2d9a4d3e4c18d88e6359853ebf1c9932279e PackageChecksum: SHA256: 0000000000000000000000000000000000000000000000000000000000000000
PackageLicenseConcluded: GPL-3.0-only PackageLicenseConcluded: GPL-3.0-only
PackageLicenseDeclared: GPL-3.0-only PackageLicenseDeclared: GPL-3.0-only
PackageCopyrightText: Copyright (C) 2006-2026 wolfSSL Inc. PackageCopyrightText: Copyright (C) 2006-2026 wolfSSL Inc.

View File

@ -22,7 +22,7 @@
"checksums": [ "checksums": [
{ {
"algorithm": "SHA256", "algorithm": "SHA256",
"checksumValue": "391e86477f5eee025e677a24b13e2d9a4d3e4c18d88e6359853ebf1c9932279e" "checksumValue": "0000000000000000000000000000000000000000000000000000000000000000"
} }
], ],
"licenseConcluded": "GPL-3.0-only", "licenseConcluded": "GPL-3.0-only",

View File

@ -30,9 +30,9 @@ Module A obligates wolfSSL Inc. to:
## Notified Body engagement — not used ## Notified Body engagement — not used
Notified Body involvement is required when a product is classified as Notified Body involvement is required for products in the higher-risk
**Annex III "important class II"** or **Annex IV "critical"**. wolfSSL libraries categories — **Annex III "important"** or **Annex IV "critical"**. wolfSSL
are neither. We have evaluated TÜV Süd as a Notified Body candidate (per libraries are neither. We have evaluated TÜV Süd as a Notified Body candidate (per
internal correspondence with our DACH team and a customer recommendation in internal correspondence with our DACH team and a customer recommendation in
May 2026) and concluded that engagement is not required for the libraries May 2026) and concluded that engagement is not required for the libraries
themselves. Customers whose finished products fall into Annex III/IV may themselves. Customers whose finished products fall into Annex III/IV may