maibornwolff/License Policy Check

The SBOM passed to the action is analyzed. If non-compliant licenses are found, the pipeline breaks optionally.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Apr 9, 2026
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: maibornwolff/purl-patrol@7d1eb703de44cd8961c4e4d321670567d523ae3c # v1.6.6

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
SBOM_PATHPath to the SBOMyes
LICENSE_POLICY_PATHPath to a custom license policy in a format compliant with sbom-utility.no
BREAK_ENABLEDBoolean value whether to break the pipeline in case of non-compliance.no
IGNORE_PKG_TYPESComma-separated list of package types to be ignoredno

no outputs