Skip to content

Conversation

@anjalitrace2-nhs
Copy link
Contributor

@anjalitrace2-nhs anjalitrace2-nhs commented Jan 23, 2026

Uses the shared trivy action to generate a new SBOM every night from develop.

The generated SBOM is stored in github as an artifact against the action run that generated it. We can also run the workflow ad-hoc if we ever cannot wait until the next scheduled run to refresh it. See our first SBOM here: https://github.com/NHSDigital/NRLF/actions/runs/21292962386 (scroll down)

Linked PR for the shared trivy action to allow an SBOM to be generated from a git repo rather than only a docker image nhs-england-tools/trivy-action#10 (merged & released in v1.4.0)

…new version published of shared trivy actions
@github-actions
Copy link

🚀 PR environment successfully deployed.
Commit Hash: 6a08c8f809b3798d13d8acdc669ab062676a68e6
URL: https://nrl1417-01ba47.api.record-locator.dev.national.nhs.uk/

@github-actions
Copy link

💥 Something went wrong while building the pull request environment.
Check Output Logs

@github-actions
Copy link

🚀 PR environment successfully deployed.
Commit Hash: d4c79238ac0db87bc8665bd2e46e3b19e4aaccc1
URL: https://nrl1417-01ba47.api.record-locator.dev.national.nhs.uk/

@anjalitrace2-nhs anjalitrace2-nhs changed the title NRL-1417 add SBOM generation step (pre-emptively) NRL-1417 add SBOM generation step to nightly build Jan 23, 2026
@sonarqubecloud
Copy link

@github-actions
Copy link

🚀 PR environment successfully deployed.
Commit Hash: d30594e574fe4ad71db5f2d1d451824ec4d5e0a4
URL: https://nrl1417-01ba47.api.record-locator.dev.national.nhs.uk/

Copy link
Contributor

@mattdean3-nhs mattdean3-nhs left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@anjalitrace2-nhs anjalitrace2-nhs merged commit 018658d into develop Jan 26, 2026
9 checks passed
@anjalitrace2-nhs anjalitrace2-nhs deleted the NRL-1417-SBOM-action branch January 26, 2026 10:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants