Skip to content

chore(sbom): remove per-app SBOM workflow + checked-in SBOM (release-asset only)#113

Merged
rubenvdlinde merged 1 commit intodevelopmentfrom
chore/sbom-release-asset-cleanup
May 1, 2026
Merged

chore(sbom): remove per-app SBOM workflow + checked-in SBOM (release-asset only)#113
rubenvdlinde merged 1 commit intodevelopmentfrom
chore/sbom-release-asset-cleanup

Conversation

@rubenvdlinde
Copy link
Copy Markdown
Contributor

Per ConductionNL/.github#34 — central Quality workflow now publishes SBOMs as release assets only. Cleans up the per-app remnants. Stable client URL: https://github.com/ConductionNL/docudesk/releases/latest/download/sbom.cdx.json

…asset only)

The central Quality workflow (ConductionNL/.github#34) now publishes SBOMs
exclusively as release assets — see SECURITY.md "Software Bill of Materials".

This PR cleans up the per-app remnants:
- delete .github/workflows/sbom.yml (the central job replaces it)
- delete the checked-in sbom.cdx.json (release asset is the source of truth)
- gitignore SBOM files so future generations don't accidentally land in repo

Stable URL for clients:
  https://github.com/ConductionNL/docudesk/releases/latest/download/sbom.cdx.json
@rubenvdlinde rubenvdlinde merged commit 5fd18b1 into development May 1, 2026
12 checks passed
@rubenvdlinde rubenvdlinde deleted the chore/sbom-release-asset-cleanup branch May 1, 2026 11:47
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 1, 2026

Quality Report — ConductionNL/docudesk @ 568c383

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 108/108
npm ✅ 529/529
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/10 statements)


Quality workflow — 2026-05-01 11:50 UTC

Download the full PDF report from the workflow artifacts.

rubenvdlinde added a commit that referenced this pull request May 3, 2026
…ob lifecycle + Archiefwet (#115)

Phase 3 of the OR-abstraction audit (2026-05-03). Spec-only — no
code changes. Drafts the per-app adoption openspec change so each
app can run /opsx-apply against it when ready.

References .claude/audit-2026-05-03/ research, Phase 2 OR/nc-vue/
hydra specs (#1420, #113, #218), and ADRs 022/024/025.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant