Skip to content

Add grype scan, SBOM and improve labeling#241

Merged
gab-arrobo merged 1 commit intoomec-project:mainfrom
sureshmarikkannu:sbom-grype
Feb 12, 2026
Merged

Add grype scan, SBOM and improve labeling#241
gab-arrobo merged 1 commit intoomec-project:mainfrom
sureshmarikkannu:sbom-grype

Conversation

@sureshmarikkannu
Copy link
Copy Markdown
Contributor

No description provided.

@sureshmarikkannu sureshmarikkannu requested a review from a team February 12, 2026 15:40
@gab-arrobo gab-arrobo requested a review from Copilot February 12, 2026 15:45
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds supply-chain security steps to the release pipeline (SBOM generation + Grype vulnerability scan) and updates release metadata/config schedules.

Changes:

  • Bump project version to 1.6.0
  • Add SBOM generation and Grype scan jobs to the GitHub Actions release workflow
  • Stagger Dependabot weekly update days across ecosystems

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
VERSION Updates the release version to 1.6.0.
.github/workflows/push.yml Extends the release pipeline with SBOM generation and a Grype scan (SARIF upload).
.github/dependabot.yml Adjusts update days and documents staggered scheduling intent.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Signed-off-by: Marikkannu, Suresh <suresh.marikkannu@intel.com>
Copy link
Copy Markdown
Contributor

@gab-arrobo gab-arrobo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

@gab-arrobo gab-arrobo merged commit 51da90a into omec-project:main Feb 12, 2026
9 checks passed
@sureshmarikkannu sureshmarikkannu deleted the sbom-grype branch February 12, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants