Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Preserve package manifests to allow SBOM generation #22048

Conversation

LaurentGoderre
Copy link

Description:

Package manifest for PHP and Javascript packages are being excluded from releases which make it difficult to generate SBOM for the release. Preserving them would make this much easier.

Review

@sgiehl
Copy link
Member

sgiehl commented Mar 26, 2024

Hey @LaurentGoderre. I understand the purpose of your PR, but we aim to keep our releases free of files that aren't needed. Most of those files are included in our repository, so if you need them, you may need to work with a Git checkout instead.

Or what could be even more interesting would be to generate some useful SBOM during a release and include the results in the release. If you are keen on helping to integrate something like that, let us know.

Copy link
Contributor

If you don't want this PR to be closed automatically in 28 days then you need to assign the label 'Do not close'.

@github-actions github-actions bot added the Stale The label used by the Close Stale Issues action label Apr 10, 2024
@sgiehl
Copy link
Member

sgiehl commented Apr 15, 2024

closing in favor of #22054

@sgiehl sgiehl closed this Apr 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Stale The label used by the Close Stale Issues action
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants