Skip to content

feature(dp-track): Add SBOM generation and upload to Dependency-Track#9

Open
AnishRF012 wants to merge 6 commits intomasterfrom
feature/dp-track
Open

feature(dp-track): Add SBOM generation and upload to Dependency-Track#9
AnishRF012 wants to merge 6 commits intomasterfrom
feature/dp-track

Conversation

@AnishRF012
Copy link
Copy Markdown

Clickup card link:

https://app.clickup.com/t/37493763/SECURITY-363

Description

This workflow automates the generation of a Software Bill of Materials (SBOM) from your package.json, requirements.txt, and pubspec.yaml files, seamlessly uploading it to Dependency Track as part of your CI/CD pipeline.

What It Tracks

  • Component Inventory: Lists all libraries and dependencies used across JavaScript, Python, and Flutter projects.

  • Vulnerability Monitoring: Identifies and tracks known vulnerabilities associated with these components.

  • Compliance Status: Ensures your software meets regulatory and security standards.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant