Skip to content

Workflow for the creation of third-party-licenses file by release - #88

Merged
anikaweinmann merged 25 commits into
mainfrom
lincenses
Sep 10, 2026
Merged

anikaweinmann merged 25 commits into
mainfrom
lincenses

Conversation

@anikaweinmann

@anikaweinmann anikaweinmann commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

anikaweinmann and others added 13 commits September 9, 2026 12:55
* Add reusable SBOM vulnerability workflow

* Add SBOM workflow documentation

* Upload vulnerability results to code scanning

* Retest reusable SBOM workflow

* update readme  SBOM vulnerability scan

* Support Dockerfile and requirements inputs

* inspect sarif locations

* Fix SARIF locations for requirements scan

* test python vulnerability scan

* upload python vulnerability results to code scanning

* add categories to vulnerabilities

* add requirements-based SBOM and vulnerability scanning

* Update SBOM workflow documentation

* update SBOM documentation

* Compare Grype scan sources

* Summarize Docker scan comparison results

* specific vulnerabilities

* Propose SBOM vulnerability scan strategy

* Support pyproject.toml for Python scans

* Document pyproject.toml support

* Make checkout fetch depth configurable

* Refine SBOM scan configuration and documentation
Comment thread .github/scripts/merge-licenses.py Outdated
Comment thread .github/scripts/merge-licenses.py Outdated
Comment thread .github/scripts/merge-licenses.py Outdated
@anikaweinmann
anikaweinmann marked this pull request as ready for review September 9, 2026 18:32
Comment thread README.md Outdated
Comment thread README.md Outdated
Comment thread README.md Outdated
Comment thread .github/workflows/third-party-licenses.yml Outdated
Comment thread .github/workflows/third-party-licenses.yml
Comment thread .github/workflows/third-party-licenses.yml Outdated
Comment thread .github/workflows/third-party-licenses.yml
shell: bash
run: |
set -euo pipefail
wget -q https://raw.githubusercontent.com/mundialis/github-workflows/refs/heads/main/.github/scripts/merge-licenses.py

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a possibility to not have main hardcoded but use what is referenced in the usage of the reusable workflow?

Comment on lines +191 to +192
# Python-Skript: scans JSON, raise warning und creates summary table
python3 - << 'PY'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If there is a solution to reference the branch/tag, maybe also make a python script out of this?

Comment thread .github/scripts/merge-licenses.py Outdated
Co-authored-by: Carmen Tawalika <mmacata@users.noreply.github.com>
@anikaweinmann
anikaweinmann merged commit 94ffb7f into main Sep 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants