cos-customizer: Automatically fetch COS image SBOM

When generating SBOM with a COS image as base image,
cos-customizer can automatically fetch SBOM from GCS
bucket cos-tools.

Updated spdx golang tool version to correctly
output field "fileAnalyzed".

Fixed Document reference in field relationships.

SBOM input and output:
https://paste.googleplex.com/5880780147392512

BUG=b/277125638
TEST=Test run a build with COS base image.
RELEASE_NOTE=None

Change-Id: I163a4d36990a26ce66a8cbc2bffde104f9fc3c11
Reviewed-on: https://cos-review.googlesource.com/c/cos/tools/+/49829
Cloud-Build: GCB Service account <228075978874@cloudbuild.gserviceaccount.com>
Tested-by: He Gao <hegao@google.com>
Reviewed-by: Robert Kolchmeyer <rkolchmeyer@google.com>
6 files changed
tree: c4da42a4ecdd1e2ba0fd3e92977221d55aa2ab0d
  1. coverage/
  2. release/
  3. src/
  4. testing/
  5. .gitignore
  6. BUILD.bazel
  7. cloudbuild.yaml
  8. CONTRIBUTING.md
  9. deps.bzl
  10. go.mod
  11. go.sum
  12. LICENSE
  13. README.md
  14. run_tests.sh
  15. WORKSPACE
README.md

Tools for Container-Optimized OS

This is a repository of various tools developed for Container-Optimized OS. Examples include cos-gpu-installer, cos-toolbox, etc.

See CONTRIBUTING.md for how to contribute.