Skip to content

Conversation

GMishx
Copy link
Member

@GMishx GMishx commented Aug 20, 2025

Description

For SBOM based scannings:

  1. Optimize license scan.
  2. Scan components one by one to keep the results separate.
  3. Generate each package and associated files in the SPDX SBOM.

Also, apply general fix required for Docker image to run on GitHub Actions.

Changes

Documented in description.

How to test

Check run logs from https://github.com/GMishx/snap-to-bucket/actions/runs/16744379992

For SBOM based scannings:
1. Optimize license scan.
2. Scan components one by one to keep the results sparate.
3. Generate each package and associated files in the SPDX SBOM.

Also, apply general fix required for Docker image to run on GitHub
Actions.

Signed-off-by: Gaurav Mishra <[email protected]>
Copy link
Member

@Kaushl2208 Kaushl2208 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes looks good.

@Kaushl2208 Kaushl2208 added this pull request to the merge queue Aug 20, 2025
Merged via the queue into fossology:master with commit 511fe33 Aug 20, 2025
13 checks passed
@Kaushl2208 Kaushl2208 deleted the fix/automation/sbom-packages branch August 20, 2025 20:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants