Skip to content

Conversation

@anjalitrace2-nhs
Copy link
Contributor

@anjalitrace2-nhs anjalitrace2-nhs commented Feb 10, 2026

  • trigger SBOM on release published rather than in nightly build
    • eventually would be nice to extend this pipeline to do our whole release but not now!
  • upload generated SBOM to github release as well as on the action
  • Our SBOM now includes:
    • python dependencies
    • terraform providers (not modules, awaiting this syft issue)
    • dependencies managed by asdf

Example

(will delete test release & tags once PR merged)

@github-actions
Copy link

🚀 PR environment successfully deployed.
Commit Hash: 6e083fe6e21ede80505d8ae284e1530a477cced6
URL: https://nrl1928-01ba47.api.record-locator.dev.national.nhs.uk/

@github-actions
Copy link

🚀 PR environment successfully deployed.
Commit Hash: d6630330ba81019740a71ad342ca6fc277786820
URL: https://nrl1928-01ba47.api.record-locator.dev.national.nhs.uk/

@sonarqubecloud
Copy link

@github-actions
Copy link

🚀 PR environment successfully deployed.
Commit Hash: 3357d1244da10c67df3e2769a7e0c9afbbb92de0
URL: https://nrl1928-01ba47.api.record-locator.dev.national.nhs.uk/

@anjalitrace2-nhs anjalitrace2-nhs merged commit e1de9a9 into develop Feb 13, 2026
9 checks passed
@anjalitrace2-nhs anjalitrace2-nhs deleted the NRL-1928-better-sbom branch February 13, 2026 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants