NRL-1417 add SBOM generation step to nightly build#1123
Merged
anjalitrace2-nhs merged 3 commits intodevelopfrom Jan 26, 2026
Merged
NRL-1417 add SBOM generation step to nightly build#1123anjalitrace2-nhs merged 3 commits intodevelopfrom
anjalitrace2-nhs merged 3 commits intodevelopfrom
Conversation
…new version published of shared trivy actions
|
🚀 PR environment successfully deployed. |
|
💥 Something went wrong while building the pull request environment. |
d4c7923 to
d30594e
Compare
|
🚀 PR environment successfully deployed. |
|
|
🚀 PR environment successfully deployed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Uses the shared trivy action to generate a new SBOM every night from develop.
The generated SBOM is stored in github as an artifact against the action run that generated it. We can also run the workflow ad-hoc if we ever cannot wait until the next scheduled run to refresh it. See our first SBOM here: https://github.com/NHSDigital/NRLF/actions/runs/21292962386 (scroll down)
Linked PR for the shared trivy action to allow an SBOM to be generated from a git repo rather than only a docker image nhs-england-tools/trivy-action#10 (merged & released in v1.4.0)