ci: attach SBOM (SPDX + CycloneDX) to every release - #28
Merged
Conversation
New sbom.yml workflow: on each published release it generates a Software Bill of Materials with syft (anchore/sbom-action, SHA-pinned) in the two standard formats and attaches them as release assets. Manual dispatch uploads them as workflow artifacts for verification. Least-privilege: top-level permissions none, contents: write only at job level.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a
sbom.ymlworkflow that, on every published release, generates a Software Bill of Materials with syft (anchore/sbom-action, SHA-pinned) in SPDX JSON and CycloneDX JSON, and attaches both as release assets.workflow_dispatchruns upload them as workflow artifacts instead (verification path).Why
Consumers can audit exactly what ships in each version. Complements GitHub's on-demand dependency-graph SBOM export (which reflects current
main, not a given release).Verification
Manual dispatch on
mainproduces valid SPDX/CycloneDX documents as artifacts; the release path activates on the next published release.