Skip to content

chore(sbom): remove per-app SBOM workflow + checked-in SBOM (release-asset only)#1386

Merged
rubenvdlinde merged 1 commit intodevelopmentfrom
chore/sbom-release-asset-cleanup
May 1, 2026
Merged

chore(sbom): remove per-app SBOM workflow + checked-in SBOM (release-asset only)#1386
rubenvdlinde merged 1 commit intodevelopmentfrom
chore/sbom-release-asset-cleanup

Conversation

@rubenvdlinde
Copy link
Copy Markdown
Contributor

Per ConductionNL/.github#34 — central Quality workflow now publishes SBOMs as release assets only. Cleans up the per-app remnants. Stable client URL: https://github.com/ConductionNL/openregister/releases/latest/download/sbom.cdx.json

…asset only)

The central Quality workflow (ConductionNL/.github#34) now publishes SBOMs
exclusively as release assets — see SECURITY.md "Software Bill of Materials".

This PR cleans up the per-app remnants:
- delete .github/workflows/sbom.yml (the central job replaces it)
- delete the checked-in sbom.cdx.json (release asset is the source of truth)
- gitignore SBOM files so future generations don't accidentally land in repo

Stable URL for clients:
  https://github.com/ConductionNL/openregister/releases/latest/download/sbom.cdx.json
@rubenvdlinde rubenvdlinde merged commit 87cb785 into development May 1, 2026
1 check passed
@rubenvdlinde rubenvdlinde deleted the chore/sbom-release-asset-cleanup branch May 1, 2026 11:49
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 1, 2026

Quality Report — ConductionNL/openregister @ 14d3722

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 147/147
npm ✅ 598/598
PHPUnit
Newman
Playwright ⏭️

Quality workflow — 2026-05-01 17:57 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant