Skip to content

feat(inventory): record built rpm sha256 in PackageId - #756

Open
jmt-lab wants to merge 1 commit into
bottlerocket-os:developfrom
jmt-lab:push-nkmsnwwxtsrp
Open

jmt-lab wants to merge 1 commit into
bottlerocket-os:developfrom
jmt-lab:push-nkmsnwwxtsrp

Conversation

@jmt-lab

@jmt-lab jmt-lab commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Description of changes:

Set the PackageId field on each application-inventory.json entry to the on-disk RPM filename plus its sha256 digest:

<name>-<version>-<release>.<arch>.rpm@sha256:<hex>

Source-package (parent) entries get an empty PackageId. A binary entry with no matching on-disk RPM aborts the build.

Testing done:

  • Built core kit and kernel kit
  • Built bob and checked application inventory for the new field.

Example Object:

{
      "Name": "whippet",
      "Publisher": "bottlerocket-core-kit",
      "Version": "0.0",
      "Release": "1.1789777546.352546d7.br1",
      "Epoch": "1",
      "InstalledTime": "2026-09-29T23:07:21Z",
      "ApplicationType": "Unspecified",
      "Architecture": "aarch64",
      "Url": "https://github.com/bottlerocket-os/bottlerocket",
      "Summary": "Custom launcher for the D-Bus message broker",
      "PackageId": "bottlerocket-whippet-0.0-1.1789777546.352546d7.br1.aarch64.rpm@sha256:3a39c8e52f9fb7211460798216d74c525300192ba993c01b72486ab834778005"
    },

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

Set the PackageId field on each application-inventory.json entry to the
on-disk RPM filename plus its sha256 digest:

    <name>-<version>-<release>.<arch>.rpm@sha256:<hex>

Source-package (parent) entries get an empty PackageId. A binary entry
with no matching on-disk RPM aborts the build.

Signed-off-by: Jarrett Tierney <jmt@amazon.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants