<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:DengXian;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"\@DengXian";
panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;
font-family:"Calibri",sans-serif;
mso-ligatures:none;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Hi folks,</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#212121">I want to share with you the latest Bomsh tool update on OmniBOR and reproducible build, especially the below bomsh_rebuild_deb.py script:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#212121"><a href="https://github.com/omnibor/bomsh/blob/main/scripts/bomsh_rebuild_deb.py" title="https://github.com/omnibor/bomsh/blob/main/scripts/bomsh_rebuild_deb.py"><span style="color:#0078D7">https://github.com/omnibor/bomsh/blob/main/scripts/bomsh_rebuild_deb.py</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#212121"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#212121">Given the Debian .buildinfo file, this script is able to reproduce the Debian package build, create the OmniBOR documents and Merkle tree, and the SPDX SBOM documents. This means the OmniBOR
documents for all the existing already-released Debian packages can be created with the Bomsh tool.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#212121"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#212121">If you are interested, you can give a try by following the link below:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#212121"><a href="https://github.com/omnibor/bomsh#Quick-Start" title="https://github.com/omnibor/bomsh#Quick-Start"><span style="color:#0078D7">https://github.com/omnibor/bomsh#Quick-Start</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Any questions, feel free to contact me.</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,</p>
<p class="MsoNormal">Yongkui</p>
</div>
</body>
</html>