devops-kung-fu / devops-kung-fu/bomber-action

Potential features to include in the action

Open
#4 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
3
Forks
1
PR merge metrics
No merged PRs in 30d

Description

So right now the action just generates an SBOM, checks for vulnerabilities and then finishes. I'm trying to think of some additional features that could be included with this action, like a flag on whether you want the vulnerability report from bomber added to the repository, or a flag to pass/fail the action if the bomber report has any vulnerabilities (or a threshold of so many severity issues, etc.).
@djschleen If there are any that sound especially good, I'd love to make a separate issue out of that and start working on new PRs to introduce features!

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue proposes several possible features but names no files, tests, or entry points. First narrow the discussion to one behavior and define its expected configuration and result; the work is done when that selected feature has agreed acceptance criteria.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, shell
Domain
ci-cd, devops
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.