Skip to content

[CI/CD]: add complete SBOM workflow from generation, augmentation, enriching, signing #422

@viveksahu26

Description

@viveksahu26

Currently, SBOMs are generated using automated tools, which could led to incorrect data or missing out data. To make sure the correctness and completeness of the SBOM data, the SBOM needs to be properly augmented and enriched. And once it is enhanced towards good quality standards, signing them ensures authenticity and trust. This workflow bridge the gap between raw SBOM generation and releasing a reliable, production-ready SBOM.

Reference: https://github.com/SBOM-Community/SBOM-Generation/blob/main/whitepaper/Draft-SBOM-Generation-White-Paper-Feb-25-2025.pdf

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions