Skip to content

Restrict SBOM upload to only Pillow JSON#9598

Merged
hugovk merged 1 commit intopython-pillow:mainfrom
radarhere:sbom
Apr 30, 2026
Merged

Restrict SBOM upload to only Pillow JSON#9598
hugovk merged 1 commit intopython-pillow:mainfrom
radarhere:sbom

Conversation

@radarhere
Copy link
Copy Markdown
Member

No description provided.

@hugovk
Copy link
Copy Markdown
Member

hugovk commented Apr 30, 2026

Are there non-Pillow *.cdx.json files?

@radarhere
Copy link
Copy Markdown
Member Author

No. My thinking was that perhaps being restrictive is better when dealing with a release.

The thought occurred to me when seeing pillow-*.cdx.json in .gitignore from #9593. You may say though that users can drag anything they want into their local copy of Pillow, but our CI is a far more controlled environment.

@hugovk hugovk merged commit 7fe1b9e into python-pillow:main Apr 30, 2026
25 checks passed
@radarhere radarhere deleted the sbom branch April 30, 2026 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants