Skip to content

Releases: SimonCropp/Sbom

0.3.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 22:32
Skip SBOM generation when no input changed

SbomGenerate is now incremental: its inputs are the project files, the lock and
assets files, the task assembly and a record of every property passed to the
task, and its output is a stamp. A build that repacks through
GeneratePackageOnBuild no longer regenerates an unchanged SBOM. When the manifest
does change, the document is serialized once and finished per timestamp.

0.3.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 21:50
Pack the SBOM as a package file instead of appending to the nupkg

The manifest is written to obj/ before GenerateNuspec and handed to NuGet as a
package file, so the nupkg is written once and never reopened. The SBOM no longer
lists the package's files. The per-framework reference call now reuses the build's
project instances instead of re-evaluating each framework.

0.2.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 12:50
Fall back to project.assets.json when there is no lock file

0.1.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 11:55