feat: prod-readiness PR 3 of 5 — supply chain & bundle integrity #76
security.yml
on: pull_request
OSV-Scanner (SCA)
7s
Trivy (filesystem + container scan)
28s
Semgrep (SAST)
28s
Gitleaks (secret scan)
12s
jscpd (duplication < 3% on touched code)
15s
SBOM (SPDX + CycloneDX)
8s
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
sbom
|
31 KB |
sha256:218d976b30895295541949e64c70bbb24ed0c7adff92b6dbb9e9cd0d83708d54
|
|