Attach an SBOM with release assets
- Dominant language
- Go
- Stars
- 9.6k
- Forks
- 954
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 42
Description
**What would you like to be added**:
This was being done, but a change to the release process caused this to stop working.
**Why is this needed**:
Syft is an SBOM generator, it should provide an SBOM of its own releases.
**Additional context**:
The `sbom-action` only triggers release uploads when running in the context of a release, or when a tag is pushed. This is no longer how the release process works, so we'll need to figure out either how to update `sbom-action` or generate and upload an SBOM in a different way.
Contributor guide
Research direction
Start by reviewing the current release process and how sbom-action handles release uploads or tag pushes. Done means Syft releases consistently include an SBOM asset despite the changed release flow.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- devops, release
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100