Skip to content

Add SBOM file generation action - #175

Open
Amruthasinchanag wants to merge 2 commits into
developfrom
users/amrutha/actor-framework-sbom-generation
Open

Amruthasinchanag wants to merge 2 commits into
developfrom
users/amrutha/actor-framework-sbom-generation

Conversation

@Amruthasinchanag

Copy link
Copy Markdown
Collaborator

GitHub Issue for the Pull Request

N/A

GitHub Discussions Related to this Pull Request

None

Checklists

  • I do not require assistance from NI to complete any of the following checks.
  • The changes in this PR are based on the appropriate NI-repo feature branch
  • I am submitting the changes in this PR to the appropriate NI-repo feature branch
  • I built a VI Package using the Powershell build tool.
  • I installed the VI Package produced by the Powershell build tool and tested my change.
  • I tested my changes after installing the VI package.
  • NI has my contributor license agreement.

Summary of Changes

This PR adds automated Software Bill of Materials (SBOM) generation for the actor-framework project via a new GitHub Actions workflow. The workflow is scheduled to run weekly (every Saturday at 10:00 UTC) and generates a CycloneDX-formatted SBOM artifact.

The workflow performs the following:

  • Resolves the product version from the latest semantic version tag in the repository
  • Calls NI's reusable SBOM generation workflow with actor-framework-specific configuration
  • Generates a CycloneDX SBOM file at builds/sbom/actor-framework.cdx.json
  • Makes the SBOM available as a downloadable artifact named actor-framework-sbom

Reason for Change

Automating SBOM generation aligns with NI's open-source security and compliance standards. Regular SBOM generation provides:

  • Consistent tracking of software components and dependencies
  • Support for vulnerability management and supply chain security
  • Alignment with industry standards (CycloneDX format)
  • Automated artifact generation for release documentation

Visual Aids

Not applicable.

Additional Information

The workflow leverages the reusable SBOM generation workflow from the ni/open-source repository. Once the reusable action is published as a release tag, the workflow reference (@actions) should be updated to pin to a specific release version for stability and reproducibility.

Testing

This section describes the automated and manual tests performed for this feature.

Automated Tests

Manual Tests

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant