Skip to content

chore(sbom): remove per-app SBOM workflow + checked-in SBOM (release-asset only)#735

Merged
rubenvdlinde merged 1 commit intodevelopmentfrom
chore/sbom-release-asset-cleanup
May 1, 2026
Merged

chore(sbom): remove per-app SBOM workflow + checked-in SBOM (release-asset only)#735
rubenvdlinde merged 1 commit intodevelopmentfrom
chore/sbom-release-asset-cleanup

Conversation

@rubenvdlinde
Copy link
Copy Markdown
Contributor

Per ConductionNL/.github#34 — central Quality workflow now publishes SBOMs as release assets only. Cleans up the per-app remnants. Stable client URL: https://github.com/ConductionNL/openconnector/releases/latest/download/sbom.cdx.json

…asset only)

The central Quality workflow (ConductionNL/.github#34) now publishes SBOMs
exclusively as release assets — see SECURITY.md "Software Bill of Materials".

This PR cleans up the per-app remnants:
- delete .github/workflows/sbom.yml (the central job replaces it)
- delete the checked-in sbom.cdx.json (release asset is the source of truth)
- gitignore SBOM files so future generations don't accidentally land in repo

Stable URL for clients:
  https://github.com/ConductionNL/openconnector/releases/latest/download/sbom.cdx.json
@rubenvdlinde rubenvdlinde merged commit 49f7729 into development May 1, 2026
10 of 17 checks passed
@rubenvdlinde rubenvdlinde deleted the chore/sbom-release-asset-cleanup branch May 1, 2026 11:49
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 1, 2026

Quality Report — ConductionNL/openconnector @ 8f50c7e

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 148/148
npm ❌ 1/573 denied
PHPUnit ⏭️
Newman ⏭️
Playwright ⏭️

❌ Denied npm licenses

Package Version License
@fortawesome/free-solid-svg-icons 6.7.2 (CC-BY-4.0 AND MIT)

Quality workflow — 2026-05-01 11:51 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant