sbomify/sbomify

A GitHub Action to upload an SBOM CycloneDX or SPDX to sbomify

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
working-dirWorking directory, relative to repo root or absolute (must be under $GITHUB_WORKSPACE). Example: packages/my-appno""
component-purlOverride the component PURL in the SBOM (e.g., pkg:npm/@scope/name@1.0.0)no
bom-typeArtifact type to record on upload: sbom (default), vex, cbom or hbom. Only the sbomify destination supports non-SBOM types; other upload-destinations entries are rejected for them. Non-SBOM types are uploaded verbatim: augmentation, enrichment, overrides, additional-package injection and the SBOM-specific finalization fixups are skipped.nosbom
oidc-audienceOIDC audience for trusted publishing (default: sbomify.com; override for self-hosted)no

no outputs