8000 risk: Added digitally signed SBOM support by mprimeaux · Pull Request #9 · sixafter/semver · GitHub
[go: up one dir, main page]

Skip to content

risk: Added digitally signed SBOM support#9

Merged
mprimeaux merged 1 commit intomainfrom
risk/sbom
Sep 15, 2025
Merged

risk: Added digitally signed SBOM support#9
mprimeaux merged 1 commit intomainfrom
risk/sbom

Conversation

@mprimeaux
Copy link
Contributor

No description provided.

@mprimeaux mprimeaux self-assigned this Sep 15, 2025
@mprimeaux mprimeaux added kind: debt Accumulated impediments that slow our ability to evolve. priority: medium labels Sep 15, 2025
@mprimeaux mprimeaux requested a review from Copilot September 15, 2025 15:30
Copy link
Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds digitally signed Software Bill of Materials (SBOM) support to enhance supply chain security and transparency for the semver Go library. It implements release artifact signing using Cosign and generates SBOMs during the release process.

  • Added Cosign public key and signing configuration for release artifacts
  • Enhanced GitHub Actions release workflow with SBOM generation and artifact signing
  • Updated documentation with verification instructions and release version 1.8.0

Reviewed Changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
cosign.pub Adds the Cosign public key for verifying signed release artifacts
README.md Updates title, adds Cosign verification section with detailed instructions
Makefile Adds release-verify target for testing release configuration
CHANGELOG.md Documents version 1.8.0 changes including SBOM support
.goreleaser.yaml Configures signing, checksums, source archives, and SBOM generation
.github/workflows/release.yaml Updates Go action version and adds Cosign/SBOM steps
.github/workflows/codeql-analysis.yaml Updates Go action to v6
.github/workflows/ci.yaml Updates Go action to v6

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@mprimeaux mprimeaux merged commit 7855976 into main Sep 15, 2025
1 check passed
@mprimeaux mprimeaux deleted the risk/sbom branch September 15, 2025 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind: debt Accumulated impediments that slow our ability to evolve. priority: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

0