Skip to content

Upload Windows SBOM sidecars named after full artifacts#404

Open
e-q wants to merge 1 commit into
python:mainfrom
e-q:upload-windows-sbom-sidecars
Open

Upload Windows SBOM sidecars named after full artifacts#404
e-q wants to merge 1 commit into
python:mainfrom
e-q:upload-windows-sbom-sidecars

Conversation

@e-q
Copy link
Copy Markdown

@e-q e-q commented Jun 2, 2026

Summary

  • look for Windows SBOM sidecars as <artifact>.spdx.json
  • place SBOM uploads next to the corresponding artifact destination
  • add a focused test for Windows upload calculation

Closes #399

Tests

  • Focused pytest coverage for Windows upload calculation: passed.
  • Ruff lint and format checks on touched files: passed.
  • Direct repository mypy check through an existing mypy environment: passed.
  • Whitespace check: passed.

@python-cla-bot
Copy link
Copy Markdown

python-cla-bot Bot commented Jun 2, 2026

All commit authors signed the Contributor License Agreement.

CLA signed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: Windows upload skips SBOM sidecars named after the full artifact

1 participant