You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There are various patterns a workflow maintainer might engage in to create and persist an SBOM. GitHub Code Search could be potentially used to identify some of those:
path:.github AND (("oras push" AND "sbom") OR "cosign attach sbom" OR /uses.*publish-sbom/)
There are various patterns a workflow maintainer might engage in to create and persist an SBOM. GitHub Code Search could be potentially used to identify some of those:
With a positive assertion done via GitHub REST API inspection of release assets or workflow artifacts.
Such a search could be expanded with BuildKit's SBOM attestation patterns:
With a positive assertion done via index traversal per current attestation storage format.
The text was updated successfully, but these errors were encountered: