Skip to content

Feat/multiple cboms#5

Merged
n1ckl0sk0rtge merged 23 commits intomainfrom
feat/multiple-cboms
Mar 10, 2025
Merged

Feat/multiple cboms#5
n1ckl0sk0rtge merged 23 commits intomainfrom
feat/multiple-cboms

Conversation

@san-zrl
Copy link
Copy Markdown
Contributor

@san-zrl san-zrl commented Mar 7, 2025

Implements additional features:

  • Scans python code (Implement python support #1 )
  • Produces multiple CBOMs (Implement package/module based CBOM generation #2):
    • One CBOM per maven/python package named cbom[_<group_id>]_<artifact_id>_<version>.json.
    • One consolidated CBOM over all source code named cbom.json
    • All CBOMs uploaded to github asset space via action variable pattern=cbom*.json
  • Includes giturl, branch, commit hash and subfolder in metadata properties of each CBOM
    -> CBOM files can be loaded into CbomKit, links to source code work correctly

Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
Signed-off-by: san-zrl <san@zurich.ibm.com>
@san-zrl san-zrl added the enhancement New feature or request label Mar 7, 2025
@san-zrl san-zrl requested a review from n1ckl0sk0rtge March 7, 2025 11:20
Copy link
Copy Markdown
Contributor

@n1ckl0sk0rtge n1ckl0sk0rtge left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@n1ckl0sk0rtge n1ckl0sk0rtge merged commit 9ee31c8 into main Mar 10, 2025
@n1ckl0sk0rtge n1ckl0sk0rtge deleted the feat/multiple-cboms branch March 10, 2025 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants