Merge SBOM CI pipelines into main#153
Merged
Merged
Conversation
* CI: scan code with trivy * run lints and tests on linux * run lint and test on x64 linux
* CI sbom implementation * include low severity vulns in sbom * upload build artifacts when tagged with version * test on sbom branch * also build on tags * pass the token to release workflow * run create-sbom job on linux * remove old upload-artifact jobs * test negative condition * tag upload conditions * uncomment testflight & play store jobs, remove sbom from triggering branches * add condition comment
* periodic sbom and advisories regeneration * pass secrets to sbom job * test periodic sbom regeneration * fix sbom workflow path * test cloning token * pass the cloning token explicitly * define release flow secrets * only generate sbom for full releases
moubctez
approved these changes
Sep 30, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.