Skip to main content

sbom-ci-enforcement

Enforce Software Bill of Materials (SBOM) generation in CI: CycloneDX and/or SPDX artifacts, build-linked attestation, publish-with-release, and hard gates when an SBOM is missing or empty. Use when wiring SBOM jobs in GitHub Actions, GitLab CI, or similar; requiring SBOM on merge/release; cosign/in-toto/SLSA attestations of SBOM-to-image; or failing pipelines that ship without inventory — hand license policy to license-compliance-scan and CVE fix clocks to vulnerability-sla-process.

Aller à l'installation

Informations de source

Dépôt
tomysh1337/openstarry-code
Dernière activité de la source
17 août 2026 à 13:35
Langue détectée de SKILL.md
anglais
Étoiles
3
Forks
0

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.