feat: native sbom generation for hcp#13566
Merged
Conversation
Updates go version
tanmay-hc
reviewed
Mar 17, 2026
tanmay-hc
reviewed
Mar 17, 2026
tanmay-hc
reviewed
Mar 17, 2026
tanmay-hc
reviewed
Mar 17, 2026
tanmay-hc
reviewed
Mar 17, 2026
galapas1
requested changes
Mar 17, 2026
galapas1
left a comment
There was a problem hiding this comment.
Thanks for the native SBOM generation feature. Summary of requested changes:
- Docs: Clarify that
sourceandauto_generateare mutually exclusive. - Validation: Consider allowing
elevated_user/elevated_passwordwhen usingsourceso users can toggle onlyauto_generatewithout clearing those fields. - Structure: Extract the retry callback into a named function for readability and testability.
- Syft version: Consider pinning to a known version with Dependabot, or document the trade-off of using "latest".
- Windows cleanup: Quote paths in
delfor paths with spaces. - Packer core: Consider delegating
FlatConfig()to the inner provisioner for consistency.
Collaborator
Author
I have made all the changes as requested, please take another look at it whenever possible. Thanks! |
Collaborator
Author
|
Oh and here's the docs for this, since we moved out to unified repo now - hashicorp/web-unified-docs#1999 |
tanmay-hc
reviewed
Mar 20, 2026
tanmay-hc
reviewed
Mar 20, 2026
tanmay-hc
reviewed
Mar 23, 2026
tanmay-hc
reviewed
Mar 23, 2026
tanmay-hc
previously approved these changes
Mar 23, 2026
galapas1
previously approved these changes
Mar 23, 2026
galapas1
left a comment
There was a problem hiding this comment.
Approved with requested edits shared via slack.
tanmay-hc
approved these changes
Mar 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR adds the native SBOM generation capability within Packer in the existing
hcp-sbomprovisioner.Packer will automatically download
syftbinary for generating the sbom. This also supports using a custom binary of your choice to generate the sbom.Relavant config options has been added to support this feature.