scf-public-goods-maintenance/PG Atlas SBOM Submission

Fetches the repo's SBOM from the GitHub Dependency Graph API and submits it to the PG Atlas ingestion endpoint, authenticated via GitHub OIDC. No secrets are shared.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
api-urlBase URL of the PG Atlas ingestion API.nohttps://api.pgatlas.xyz
submission-pathAPI endpoint for SBOM ingestion.no/ingest/sbom
dry-runIf true, fetch the SBOM and obtain the OIDC token, but skip the final submission. Useful for testing action setup without sending data. nofalse
namedescription
sbom-pathPath to the SBOM file that was fetched (SPDX 2.3 JSON).