Skip to content

chore: prepare for Hex publishing with release workflow and security scanning#8

Merged
Taure merged 1 commit intomainfrom
chore/hex-ready
Mar 15, 2026
Merged

chore: prepare for Hex publishing with release workflow and security scanning#8
Taure merged 1 commit intomainfrom
chore/hex-ready

Conversation

@Taure
Copy link
Contributor

@Taure Taure commented Mar 15, 2026

Summary

  • Add rebar3_hex, rebar3_audit, rebar3_sbom to project plugins
  • Replace custom release workflow with reusable Taure/erlang-ci release (git-cliff based changelog)
  • Add cliff.toml for conventional commit changelog generation
  • Enable audit, SBOM generation, SBOM vulnerability scan (Grype), dependency submission, and PR summary in CI

Test plan

  • Verify CI passes with new audit/SBOM/summary flags
  • Verify release workflow triggers on merge to main
  • Test rebar3 hex build produces valid package

…scanning

- Add rebar3_hex, rebar3_audit, rebar3_sbom to project plugins
- Switch release workflow to reusable Taure/erlang-ci release (git-cliff)
- Add cliff.toml for conventional commit changelog generation
- Enable audit, SBOM, SBOM scan, dependency submission, and summary in CI
@Taure Taure force-pushed the chore/hex-ready branch from 4664509 to 03f294d Compare March 15, 2026 15:42
@github-actions
Copy link

📦 SBOM Scan

No vulnerabilities found.

@Taure Taure merged commit 0ad5143 into main Mar 15, 2026
22 checks passed
@Taure Taure deleted the chore/hex-ready branch March 15, 2026 15:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant