Skip to content

Conversation

@j-chmielewski
Copy link
Contributor

No description provided.

* implement & test sbom files creation during CI process

* add sbom workflow file

* strip 'v' from ref_name

* fix version stripping

* rename sbom file

* fix asset path

* spdx format

* uncomment build-binaries job

* run sbom on self-hosted workers

* use shogo82148/actions-upload-release-asset upload action
* CI: scan code with trivy

* update e2e pnpm deps

* update web dependencies

* configure trivy scan-ref

* include low severity vulns in sbom
* regenerate sboms and advisories periodically

* fix sbom file name

* remove branch push trigger
j-chmielewski and others added 4 commits September 30, 2025 09:50
…in permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…in permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@j-chmielewski j-chmielewski merged commit 39a9998 into main Sep 30, 2025
7 checks passed
@j-chmielewski j-chmielewski deleted the sbom-into-main branch September 30, 2025 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants