Supply-chain rules for Bazel
This repository contains Bazel modules for injecting and collecting supply-chain metadata into builds.
This project is the successor to rules_license.
The intended use cases are:
- declaring metadata about packages, such as
- the licenses the package is available under
- the canonical package name and version
- copyright information
- ... and more TBD in the future
- gathering license declarations into artifacts to ship with code
- applying organization specific compliance constriants against the
set of packages used by a target.
- producing SBOMs for built artifacts.
[!WARNING]
The code here is still in active initial development and will churn a lot.
How to participate
Roadmap
See this page.
Background reading:
These are for learning about the problem space, and our approach to solutions. Concrete specifications will always appear in checked in code rather than documents.