Skip to content

Conversation

@j-chmielewski
Copy link
Contributor

No description provided.

j-chmielewski and others added 26 commits September 30, 2025 09:41
* implement & test sbom files creation during CI process

* add sbom workflow file

* strip 'v' from ref_name

* fix version stripping

* rename sbom file

* fix asset path

* spdx format

* uncomment build-binaries job

* run sbom on self-hosted workers

* use shogo82148/actions-upload-release-asset upload action
* CI: scan code with trivy

* update e2e pnpm deps

* update web dependencies

* configure trivy scan-ref

* include low severity vulns in sbom
* regenerate sboms and advisories periodically

* fix sbom file name

* remove branch push trigger
…in permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…in permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Merge SBOM CI pipelines into main
* verify API tests

* verify client activation access

* always allow device creation during client activation

* reuse existing extractor
Updated readme to include security pages.
* fix trivy advisories generation

* use pnpm v10.18
* update proxy e2e tests for new ui

* add max failures

* remove docker check

* fix password reset test
@j-chmielewski j-chmielewski merged commit cc477fd into dev Oct 31, 2025
4 checks passed
@j-chmielewski j-chmielewski deleted the merger-pre-1.6 branch October 31, 2025 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants