Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement and generate Software Bill of Materials (SBOM) manifest in pull request pipeline. #648

Merged
merged 95 commits into from
Feb 16, 2022

Conversation

vidyambala
Copy link
Contributor

Description

Implement and generate Software Bill of Materials (SBOM) manifest in pull request pipeline.

Issue reference

The issue this PR will close: #607

Checklist

Please make sure you've completed the relevant tasks for this PR out of the following list:

  • All acceptance criteria in the backlog item are met
  • The documentation is updated to cover any new or changed features
  • Manual tests have passed
  • Relevant issues are linked to this PR

brooke-hamilton and others added 30 commits February 8, 2022 16:16
@vidyambala
Copy link
Contributor Author

/azp run

@azure-pipelines
Copy link

Azure Pipelines could not run because the pipeline triggers exclude this branch/path.

@vidyambala
Copy link
Contributor Author

/azp run

@azure-pipelines
Copy link

Azure Pipelines could not run because the pipeline triggers exclude this branch/path.

@glennmusa glennmusa self-assigned this Feb 15, 2022
@brooke-hamilton brooke-hamilton enabled auto-merge (squash) February 16, 2022 13:44
vidyambala and others added 3 commits February 16, 2022 08:45
Co-authored-by: Glenn Musa <4622125+glennmusa@users.noreply.github.com>
Co-authored-by: Glenn Musa <4622125+glennmusa@users.noreply.github.com>
Co-authored-by: Glenn Musa <4622125+glennmusa@users.noreply.github.com>
@glennmusa
Copy link
Contributor

/azp run

@azure-pipelines
Copy link

Azure Pipelines could not run because the pipeline triggers exclude this branch/path.

@glennmusa
Copy link
Contributor

glennmusa commented Feb 16, 2022

Do you have any prompts from the Microsoft CLA bot to accept the contributors license agreement, @vidyambala? I noticed this hanging CLA check is happening for your other PR #651 as well.

@brooke-hamilton brooke-hamilton merged commit 6634eba into main Feb 16, 2022
@brooke-hamilton brooke-hamilton deleted the brooke/sbom-pipeline branch February 16, 2022 20:10
Breanna-Stryker added a commit that referenced this pull request Feb 21, 2022
* Check that Portal UI form outputs map to template parameter inputs on pull requests (#620)

* Move the workflow scripts to where they're used (#632)

* Update descriptions in alt text on main README.md (#633)

* Add spike issue template and remove feature request issue template (#635)

* Fix for Terraform issue in which the tier 2 subscription parameter is ignored (#638)

* Process for handling a broken build (#641)

* Clean-up nightly deployments using Azure CLI (#642)

* Add instructions for ASC/Defender cleanup (#643)

* Pin Bicep to v0.4.1272 (#650)

* SBOM generation in PR (#648)

* Update policy assignment resource provider version (#652)

* Generate SBOMs without .git contents (#654)

* Generate SBOM files during PR events (#656)

* check to see if the SBOM needs to be regenerated before running the pipeline again

* Update Software Bill of Materials (SBOM)

Co-authored-by: Microsoft.VisualStudio.Services.TFS <>

Co-authored-by: Glenn Musa <4622125+glennmusa@users.noreply.github.com>
Co-authored-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Vidya Bala <vidbala@microsoft.com>
Co-authored-by: JeromeJansen <jjansen23@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Generate a bill of materials in a pipeline
3 participants