Skip to content

Generate Software Bill of Materials#6657

Merged
Vinnl merged 1 commit into
mainfrom
ssdlc-sbom
May 20, 2026
Merged

Generate Software Bill of Materials#6657
Vinnl merged 1 commit into
mainfrom
ssdlc-sbom

Conversation

@Vinnl
Copy link
Copy Markdown
Collaborator

@Vinnl Vinnl commented May 19, 2026

See this Slack message where I volunteered us to try out this new tooling, described here :) (Edit: haha, I see @groovecoder volunteered us as well.)

Essentially, all this does is generate a JSON file on every release listing all our dependencies in a standard format that will give the security team more insights across Mozilla projects. Here's a test run if you want to see what the output looks like. Dependabot is already configured to update the Action to a new version if one is released.

@codemist
Copy link
Copy Markdown
Collaborator

@Vinnl Cool! Didn't get a chance to see the Slack message. Interested to see what kind of feedback this will give us.

Copy link
Copy Markdown
Member

@groovecoder groovecoder left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This workflow looks good for blurts-server. Though I brought up a broader issue about ssdlc-sbom workflow in Slack here: https://mozilla.slack.com/archives/C0AD40DUXGU/p1779201088733919

@Vinnl Vinnl added this pull request to the merge queue May 20, 2026
Merged via the queue into main with commit 5248e88 May 20, 2026
19 checks passed
@Vinnl Vinnl deleted the ssdlc-sbom branch May 20, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants