SBOM generation as part of release management
GitHub increasingly enhances the visibility of your repository’s current status through its insights feature, which is available for organizations and individual repositories. However, one limitation is the inability to easily track the specific version of software running in a release, particularly when branches and deployed versions diverge. Understanding the composition of your software’s supply chain is essential for effectively communicating about significant updates or identifying areas that require patches.
For repositories with advanced security features or Dependabot enabled, Dependency graph in the Insights tab offers supply chain insights. This feature visually represents the repository’s dependencies and allows an SBOM to be generated via a simple button click:
Figure 16.5 – Dependency graph
While this is helpful, it becomes challenging when we’re dealing with...