Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SBOM generation and inclusion #20

Merged
merged 2 commits into from
Jun 21, 2023
Merged

SBOM generation and inclusion #20

merged 2 commits into from
Jun 21, 2023

Conversation

mbish
Copy link
Contributor

@mbish mbish commented Jun 20, 2023

Generate SBOM in github actions and include result in distributions

Description

In order to have better visibility into the software supply chain of duo_universal_python
we're adding an SBOM file with a breakdown of each dependency.

Motivation and Context

This is motivated by a desire to have better supply chain visibility.

How Has This Been Tested?

The script has been tested manually locally, testing through github actions is still in process

Types of Changes

  • New feature (non-breaking change which adds functionality)

@mbish
Copy link
Contributor Author

mbish commented Jun 20, 2023

https://github.com/mbish/duo_universal_python/actions/runs/5327135104/jobs/9650104543 - Release created on fork includes spdx.json in artifact creation.

@mbish mbish marked this pull request as ready for review June 20, 2023 20:35
@AaronAtDuo AaronAtDuo merged commit eacb8dd into main Jun 21, 2023
5 checks passed
@AaronAtDuo AaronAtDuo deleted the sbom branch June 21, 2023 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants