Skip to content

ci: release pipeline with CycloneDX SBOM - #89

Closed
eaglei15 wants to merge 5 commits into
mainfrom
feat/release-sbom-pipeline
Closed

eaglei15 wants to merge 5 commits into
mainfrom
feat/release-sbom-pipeline

Conversation

@eaglei15

@eaglei15 eaglei15 commented Jul 20, 2026 •

Copy link
Copy Markdown
Collaborator

What

Adds .github/workflows/release.yml — a release pipeline that fires on every pushed v* tag and:

  1. Installs the project into an isolated virtualenv.
  2. Generates a CycloneDX SBOM of the project's Python runtime environment via cyclonedx-py environment (run isolated with pipx so the SBOM tool itself is excluded).
  3. Creates a GitHub Release for the tag with auto-generated notes and attaches bom.json.

Usage

git tag v1.0.3
git push origin v1.0.3

Notes

  • The SBOM command uses --output-format JSON --output-file bom.json. Note the CLI flag is --output-format (alias --of), not --format, in current cyclonedx-bom.
  • Verified locally: produces a 93-component SBOM including torch and cyclonedx-python-lib, excluding the SBOM tooling.
  • Requires no extra secrets — uses the built-in GITHUB_TOKEN with contents: write.

eaglei15 added 5 commits July 20, 2026 16:36
… SBOM

On every pushed v* tag, install the project into an isolated venv,
generate a CycloneDX SBOM of its Python runtime environment with
cyclonedx-py, and create a GitHub Release with the bom.json attached.
@eaglei15

Copy link
Copy Markdown
Collaborator Author

Superseded by #90, which is rebased cleanly onto the latest main and adds release-artifact building plus artifact hash capture in the SBOM.

@eaglei15 eaglei15 closed this Jul 21, 2026
@eaglei15
eaglei15 deleted the feat/release-sbom-pipeline branch July 21, 2026 00:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant