Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This Pull Request is the first step to close #175 . The goal is to highlight how SBOMs can be easily created via the CI/CD and can be uploaded. In order to show this, I added a workflow called sbom.yml which generates a set of 2 SBOMs, one for each current format (SPDX, CycloneDX).
Sidenote: I opted to use alpine:latest instead of directly going with the ubuntu runners, as it is more lightweight and has therefore less dependencies. I am still considering if moving away from :latest and doing a proper version pin is better, if we already go the extra mile to use a more lightweight container.