Repository navigation
[2026] Stabilize Cargo SBOM #472
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
9 commits
Select commit
Hold shift + click to select a range
13c6f90
Add 2026/stabilize-cargo-sbom.md
Shnatsel ff52ed4
Link tracking issue
Shnatsel 256fe79
Fix editing goof
Shnatsel 9f1d195
Mention getting the RFC accepted
Shnatsel 49432fa
Move tracking issue to "other tracking issues" to hopefully pass CI
Shnatsel 927d01e
Bump Team ask to medium to account for RFC process
Shnatsel c77d78c
apply review suggestion
Shnatsel d6ccd65
apply review suggestion: Cargo champion
Shnatsel c206bd0
apply review suggestion: fix typo
Shnatsel File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,64 @@ | ||
| # Stabilize Cargo SBOM precursor | ||
|
|
||
| | Metadata | | | ||
| | :--------------- | -------------------------------------------------------------------------------- | | ||
| | Point of contact | @Shnatsel | | ||
| | Status | Proposed for mentorship | | ||
| | Tracking issue | | | ||
| | Other tracking issues | https://github.com/rust-lang/cargo/issues/16565 | | ||
| | Zulip channel | N/A | | ||
| | [cargo] champion | TBD | | ||
|
|
||
| ## Summary | ||
|
|
||
| Progress towards an MVP version of Cargo SBOM support by resolving known issues in Cargo's [SBOM precursor feature](https://doc.rust-lang.org/nightly/cargo/reference/unstable.html#sbom) and finalizing the RFC. | ||
|
|
||
| ## Motivation | ||
|
|
||
| [Software Bill of Materials](https://en.wikipedia.org/wiki/Software_supply_chain) is a list of project dependencies and their versions, analogous to Cargo.lock, in a format standardized across programming languages. They enable supply chain transparency and allow easily identifying dependencies with known vulnerabilities. | ||
|
|
||
| SBOMs are turning from a best practice to being mandatory. In the US [Executive Order 14028](https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity) requires the federal government to only purchase software from vendors who provide a Software Bill of Materials for each product. In the EU the [Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj) mandates that any product with "digital elements" sold in the EU must have an SBOM as part of its technical documentation; obligations for reporting vulnerabilities begin in September 2026, with full compliance required by December 2027. Many other jurisdictions have similar regulations. | ||
|
|
||
| ### The status quo | ||
|
|
||
| The crucial missing piece for SBOM generation for Rust+Cargo projects is accurate reporting of the dependency tree. `cargo metadata` falls short in [multiple](https://github.com/rust-lang/cargo/issues/7754) [ways](https://github.com/rust-lang/cargo/issues/10718). This results in either false negatives or false positives in the reported dependency tree. | ||
|
|
||
| The [SBOM precursor](https://doc.rust-lang.org/nightly/cargo/reference/unstable.html#sbom) feature in Cargo addresses this by providing a mechanism to accurately report the dependency tree used in a given build. However, it is nightly-only, not yet widely used, and has [at least one known issue](https://github.com/rust-lang/cargo/issues/15695). | ||
|
|
||
| Inaccurate SBOMs lead to false positives on vulnerability scans and/or compliance issues. | ||
|
|
||
| ### What we propose to do about it | ||
|
|
||
| 1. Complete [the RFC](https://github.com/rust-lang/rfcs/pull/3553) for this feature and get it accepted | ||
| 1. Resolve the already known issue(s) in the Cargo SBOM precursor feature | ||
| 1. Modify [cargo-cyclonedx](https://crates.io/crates/cargo-cyclonedx) to use the Cargo SBOM precursor as a data source, to prove that it can be used to generate a complete and accurate SBOM in an industry standard format | ||
| 1. Address any issues that point 2 uncovers in the Cargo SBOM precursor feature | ||
| 1. Stabilize the MVP that is sufficient to power [cargo-cyclonedx](https://crates.io/crates/cargo-cyclonedx) and [cargo-auditable](https://github.com/rust-secure-code/cargo-auditable) | ||
|
|
||
| ### Work items over the next year | ||
|
|
||
| | Task | Owner(s) | Notes | | ||
| | ----------- | -------- | ----- | | ||
| | Complete the RFC | @Shnatsel et al. | | | ||
| | Resolve known issues | @Shnatsel et al. | | | ||
| | convert cargo-cyclonedx to use the SBOM precursor | @Shnatsel et al. | outside the Rust Project repositories, no Rust Project mentorship needed | | ||
| | Resolve newly uncovered issues | @Shnatsel et al. | | | ||
| | Stabilize the MVP | @Shnatsel et al. | | | ||
|
|
||
| I am in the process of applying for funding for this work, together with collaborators I'm not sure I can disclose. The amount of time we can dedicate to the project will depend on the outcome of that application. It is possible that the funding will only materialize in the second half of the year or not at all. | ||
|
|
||
| ## Team asks | ||
|
|
||
| We will need: | ||
|
|
||
| - Guidance to get the RFC finalized and accepted | ||
| - A handful of 30-minute design meetings with someone on the Cargo team to guide fixing the implementation issues | ||
| - Guidance on the stabilization process | ||
|
|
||
| | Team | Support level | Notes | | ||
| | ---------- | ------------- | --------------------------------------- | | ||
| | [cargo] | Medium | | | ||
|
|
||
| ## Frequently asked questions | ||
|
|
||
| TODO - will fill in based on the review comments | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.