feat(mobile): publish per-artifact CycloneDX SBOMs on release - #6665
Conversation
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryThe commits since the prior review are the merge of Files Reviewed (2 files)
Previous Review Summaries (4 snapshots, latest commit 3d995ac)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 3d995ac)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commits add iOS embedded-app-extension dependency walking, a plist-fallback executable resolver, idempotent tag/release publication with Files Reviewed (4 files)
Previous review (commit 1640335)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental changes add an OS-provided-library filter to the iOS IPA reader so Files Reviewed (4 files)
Previous review (commit e343993)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental changes resolve all prior findings in Files Reviewed (4 files)
Previous review (commit 11faaf3)Status: 4 Issues Found | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (15 files)
Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
6fbc2fc to
1987fc3
Compare
|
kilo-review — independent audit of the published diff. Status: 1 Issues
|
The evidence-reproduction block mixed roots: `node scripts/mobile-sbom.mjs` resolves only from the repository root, while `artifacts/app.ipa`, `build.json` and `--out-dir artifacts` are the apps/mobile-relative paths the release workflow uses. Rewrite both commands root-relative so each one can be pasted as printed, and name the Podfile.lock a local prebuild generates.
|
Audit finding validated and already fixed in
A follow-up docs fix is in |
The IPA scan read only the main app executable and the app's top-level Frameworks/ directory, so a framework or dylib that only an embedded PlugIns/*.appex extension uses never reached the iOS SBOM. Each extension bundle is now walked the same way: its executable's load commands, then its own Frameworks/ directory. An extension whose plist cannot be read falls back to the bundle name, and the result is checked against the file system, so a bundle with no dependencies cannot be reported silently.
The release tag is deterministic, so a rerun of the same commit recomputed the tag the failed attempt had pushed and died at the tag step. The tag step now reuses a tag that already exists on origin, and the publication step updates the release and re-uploads the CycloneDX assets with --clobber when the release already exists, so a failed upload can be retried.
The added fixture code was not oxfmt-shaped, which failed format-check.
|
Audit finding ( |
…ct-sbom-067e # Conflicts: # .github/workflows/kilo-app-release.yml # package.json
Changelog for users
kilo-app-<platform>-<version>-build<buildNumber>.cyclonedx.json.kilo-app-release/<date>-<sha>tag.gh release download kilo-app-release/<date>-<sha> -p '*.cyclonedx.json'.Changelog for maintainers
.github/workflows/kilo-app-release.yml, jobbuild-and-submit, onpushtomainfiltered toapps/mobile/**and its workspace inputs, orworkflow_dispatch, gated onshould_build == true && github.ref == 'refs/heads/main'.kilo-app-release/<date>-<sha>release plus the retained workflow artifactmobile-sbom-<sha>(90 days);.gitignoreignores/apps/mobile/artifacts/.docs/sbom.md"Coverage limits" section states each gap; nothing claims full coverage, and there is no CVE threshold or--fail-on.if:and nocontinue-on-error, so an undocumented build fails the job before it is submitted.apps/mobilefrompnpm-lock.yaml(dependencies plus optionalDependencies,link:/file:workspace recursion, npm aliases resolved to the real package); a package Metro bundles but the graph does not declare is not listed.LC_LOAD_DYLIB/weak/reexport/upward load commands plusPayload/*.app/Frameworks/;--podfile-lockprints declared, visible, and missing pods. Statically linked pods are invisible, so the artifact list is a lower bound.BUNDLE-METADATA/com.android.tools.build.libraries/dependencies.pbthrough a small direct protobuf reader (noprotobufjsimport), plusbase/lib/**/*.so.scripts/mobile-sbom-workflow.test.mjspins the step wiring and the ignore rules, and the repo-widesbom.ymlfamily is untouched.E2E proof
No production build was triggered from this work, and no EAS-downloaded IPA or AAB was available, so the generator was exercised against synthesized fixtures through its integration tests rather than a real shipped artifact. That leaves the run inside the release job and every real-artifact measurement unproven here.
Affected test suites, from this section's check log, all pass:
The generator's integration test drives the real CLI end to end on a synthesized IPA, AAB, and build record, and asserts one CycloneDX document per platform, the four linkage fields, the artifact SHA-256 against the fixture bytes, and that corrupt dependency metadata fails with no document written.
Retrieve an SBOM for a build:
Measured per-ecosystem counts and the iOS
Podfile.lockgap are not reported here because no real artifact was processed. Each production build writes them into its release notes, anddocs/sbom.mdgives the commands to reproduce them.Owner request