Skip to content

SBOM with CycloneDx struct #467

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 37 commits into from
Jun 19, 2025
Merged

SBOM with CycloneDx struct #467

merged 37 commits into from
Jun 19, 2025

Conversation

attiasas
Copy link
Contributor

@attiasas attiasas commented Jun 12, 2025

  • The pull request is targeting the dev branch.
  • The code has been validated to compile successfully by running go vet ./....
  • The code has been formatted properly using go fmt ./....
  • All static analysis checks passed.
  • All tests have passed. If this feature is not already covered by the tests, new tests have been added.
  • Updated the Contributing page / ReadMe page / CI Workflow files if needed.
  • All changes are detailed at the description. if not already covered at JFrog Documentation, new documentation have been added.

Replace old Sbom struct with github.com/CycloneDX/cyclonedx-go and adjust logic
Adding utilities for handling CycloneDX

@attiasas attiasas added the ignore for release Automatically generated release notes label Jun 12, 2025
@attiasas attiasas added the safe to test Approve running integration tests on a pull request label Jun 15, 2025
@github-actions github-actions bot removed the safe to test Approve running integration tests on a pull request label Jun 15, 2025
@attiasas attiasas added the safe to test Approve running integration tests on a pull request label Jun 16, 2025
@github-actions github-actions bot removed the safe to test Approve running integration tests on a pull request label Jun 16, 2025
@attiasas attiasas mentioned this pull request Jun 18, 2025
7 tasks
Copy link
Contributor

@hadarshjfrog hadarshjfrog left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great job here to a massive change 👏

Added some comments and mostly questions.

One thing that reoccured - please go over what you define as the main flows of the process, and especially the one that we're more tricky while coding and testing it - and add logs - mostly DEBUG - but I can think of a few INFO

@attiasas attiasas added the safe to test Approve running integration tests on a pull request label Jun 19, 2025
@github-actions github-actions bot removed the safe to test Approve running integration tests on a pull request label Jun 19, 2025
Copy link

👍 Frogbot scanned this pull request and did not find any new security issues.


@attiasas attiasas requested a review from hadarshjfrog June 19, 2025 11:51
@attiasas attiasas merged commit 7405e49 into jfrog:dev Jun 19, 2025
128 of 159 checks passed
@attiasas attiasas deleted the sbom_with_cdx branch June 19, 2025 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ignore for release Automatically generated release notes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants