-
Notifications
You must be signed in to change notification settings - Fork 53
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
SBOM and license scanning information and monitor fixes (#775)
This PR adds SBOM information to README as well as [CLOMonitor](https://github.com/cncf/clomonitor) exemption configuration. This resolves #551 and #546
- Loading branch information
Showing
2 changed files
with
23 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,19 @@ | ||
# CLOMonitor metadata file | ||
|
||
# Checks exemptions | ||
exemptions: | ||
- check: artifacthub_badge | ||
reason: "Nephio artifacts are hosted on DockerHub" | ||
|
||
- check: signed_releases | ||
reason: > | ||
"All Nephio release images are cryptographically signed during build with cosign. | ||
Images and signatures are hosted in DockerHub. Naming convention is that signature | ||
filename is an image sha256 digest and the file extension is .sig | ||
Scorecard check is currently limited to repositories hosted on GitHub, | ||
and does not support other source hosting repositories." | ||
licenseScanning: | ||
# In Nephio every PR is being tested for license compliance. Those include Fossology scan, Scancode-toolkit scan and | ||
# Lichen scan of produced binaries. The results of those scans are available at Prow site: | ||
url: https://prow.nephio.io/ |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters