Skip to main content

sbom-ci-enforcement

Enforce Software Bill of Materials (SBOM) generation in CI: CycloneDX and/or SPDX artifacts, build-linked attestation, publish-with-release, and hard gates when an SBOM is missing or empty. Use when wiring SBOM jobs in GitHub Actions, GitLab CI, or similar; requiring SBOM on merge/release; cosign/in-toto/SLSA attestations of SBOM-to-image; or failing pipelines that ship without inventory — hand license policy to license-compliance-scan and CVE fix clocks to vulnerability-sla-process.

跳到安装

来源信息

仓库
tomysh1337/openstarry-code
最近来源活动
2026年8月17日 13:35
检测到的 SKILL.md 语言
英语
星标
3
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。