Skip to content

ci: add SBOM review check#38

Merged
Christian R (antiphp) merged 2 commits intomainfrom
cr/sbom
Jan 23, 2026
Merged

ci: add SBOM review check#38
Christian R (antiphp) merged 2 commits intomainfrom
cr/sbom

Conversation

@antiphp
Copy link
Contributor

Goal of this PR

Adds license check. No severity configured so we fallback to the recommended default.

How did I test it?

@antiphp Christian R (antiphp) self-assigned this Jan 23, 2026
Copilot AI review requested due to automatic review settings January 23, 2026 09:50
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds an SBOM/dependency license review check to the CI pipeline for pull requests, enforcing a deny-list of AGPL licenses via GitHub’s dependency review action.

Changes:

  • Introduces a new SBOM GitHub Actions workflow triggered on pull_request.
  • Adds a license job that runs actions/dependency-review-action@v4 with a deny-licenses list of AGPL SPDX identifiers.
  • Configures minimal permissions (contents: read) for the workflow, consistent with the existing CI setup.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@antiphp Christian R (antiphp) merged commit ee37e4e into main Jan 23, 2026
16 checks passed
@antiphp Christian R (antiphp) deleted the cr/sbom branch January 23, 2026 10:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments