Security
SBOM
Quick answer
An SBOM is a machine-readable inventory of every component and dependency contained in a piece of software.
Also: Software bill of materials
An SBOM is a machine-readable inventory of every component and dependency contained in a piece of software.
Why it matters
Generating one during the build is the only reliable moment — afterwards you are guessing. SPDX and CycloneDX are the two formats worth supporting.
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.
Related
Audit logAn audit log is an append-only record of configuration and access changes, capturing who did what, when, and from where.Data residencyData residency is the requirement that data be stored and processed within a defined geographic boundary.GitHub AppA GitHub App is an integration that authenticates as itself with scoped, short-lived installation tokens rather than as a user.GITHUB_TOKENGITHUB_TOKEN is the automatically generated, short-lived token available to every workflow run for authenticating to the GitHub API.