Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Publish Flux Software Bill of Materials (SBOM) #2295

Merged
merged 1 commit into from
Jan 17, 2022
Merged

Conversation

stefanprodan
Copy link
Member

@stefanprodan stefanprodan commented Jan 14, 2022

Changes to the release workflow:

  • generate SBOM for Flux Go modules with Syft
  • publish the SBOM SPDX JSON files to GitHub releases with GoReleaser

Depends on: fluxcd/pkg#219
Ref: #2302

@stefanprodan stefanprodan added the area/ci CI related issues and pull requests label Jan 14, 2022
@stefanprodan stefanprodan requested a review from hiddeco January 14, 2022 07:50
@stefanprodan stefanprodan changed the title Publish Flux Software Bill of Materials (SBOM) in SPDX format Publish Flux Software Bill of Materials (SBOM) Jan 14, 2022
Copy link
Member

@hiddeco hiddeco left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM for an initial introduction, thanks @stefanprodan 🙇

@stefanprodan stefanprodan force-pushed the sbom-spdx branch 2 times, most recently from 23a2448 to b8617ed Compare January 14, 2022 14:35
- generate SBOM for Flux Go modules with Syft
- publish the SBOM SPDX JSON files to GitHub releases with GoReleaser

Signed-off-by: Stefan Prodan <stefan.prodan@gmail.com>
@stefanprodan stefanprodan merged commit 6ceb8d8 into main Jan 17, 2022
@stefanprodan stefanprodan deleted the sbom-spdx branch January 17, 2022 08:33
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
area/ci CI related issues and pull requests
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants