greenbone / openvas-smb

SMB module for OpenVAS Scanner
GNU General Public License v2.0
47 stars 47 forks source link

Added composite action SPDX to dependency graph #57

Closed ghost closed 1 year ago

ghost commented 1 year ago

What

Implementing SPDX to Dependency Graph Action.

Why

Improve security posture via the Github Enterprise Advanced Security action to makes it easy to upload an SPDX 2.2 formatted SBOM to GitHub's dependency submission API. This lets you quickly receive Dependabot alerts for package manifests which GitHub doesn't directly support like pnpm or Paket by using existing off-the-shelf SBOM generators.

References

Related to Jira DEVOPS-622 More info spdx-dependency-submission-action

Checklist