Skip to content

Improve SBOM artifact stage and scope analysis#1609

Open
NiXouuuu wants to merge 1 commit into
UnitOneAI:mainfrom
NiXouuuu:improve/sbom-artifact-stage-scope
Open

Improve SBOM artifact stage and scope analysis#1609
NiXouuuu wants to merge 1 commit into
UnitOneAI:mainfrom
NiXouuuu:improve/sbom-artifact-stage-scope

Conversation

@NiXouuuu
Copy link
Copy Markdown

@NiXouuuu NiXouuuu commented Jun 7, 2026

Closes #1608.

Summary

  • Add an explicit artifact-stage gate before SBOM vulnerability priority and license classification.
  • Add component-scope bucketing for runtime, optional runtime, dev/test, build-only, excluded, and unknown-scope components.
  • Update transitive dependency, license analysis, findings classification, output format, common pitfalls, and prompt-injection guardrails to keep runtime risk separate from source/build/test inventory.

Validation

  • git diff --check
  • Markdown fence-balance check for skills/vuln-management/sbom-analysis/SKILL.md
  • Required marker check for artifact-stage, component-scope, runtime dependency, unknown-scope, and v1.1.0 output additions

Payment preference: PayPal; details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] sbom-analysis: add dependency scope and artifact-stage gates

1 participant