Urgent.News

What's breaking now, across thousands of outlets.

Science

Turn Trivy SBOM and SARIF output into versioned release evidence

Security tools already generate useful evidence. The problem at release time is often not another scan. It is proving which SBOM, test run, security report and code change belonged to one exact software version. CRA Release Evidence is a free, MIT-licensed GitHub Action for that narrow job. It reads files already present in the current workflow workspace and writes a version-specific EVIDENCE.md…

Releasing software often requires more than just scanning for security vulnerabilities. One crucial aspect is providing a detailed record of the SBOM, test results, security reports and code changes for a specific software version. Enter CRA Release Evidence, a free, MIT-licensed GitHub Action designed to streamline this process.

The tool works by reading existing files in the current workflow workspace and generating a version-specific EVIDENCE.md, evidence.json, changes.json, SHA-256 manifest, and SBOM directory. Crucially, it is not a scanner, legal advisor, conformity assessor, or compliance verdict-generator. The responsibility for these aspects remains with the humans involved.

The example workflow provided demonstrates running Trivy twice on the released revision: once for generating CycloneDX output as the SBOM and once for producing SARIF output as indexed security-scan evidence. Both files are then bound to the release tag, checked-out commit, and Git change summary by CRA Release Evidence.

Two output formats are used because CycloneDX addresses the inventory question while SARIF carries the findings. The evidence collector does not interpret findings or automatically accept risk; it merely records the existence of configured categories, the revision declared by the workflow, a neutral summary, and a SHA-256 digest. Raw SARIF is not included unless explicitly requested.

The SBOM generated by the collector is always part of the package and may reveal product structure, so the artifact's destination and retention still require review. Before integrating this collector, the author recommends adding tests without altering the model and exploring additional test results from previous jobs by downloading them into the workspace.

For more detailed instructions and a full setup guide, visit the official documentation at https://github.com/mastermuetze/cra-release-evidence/blob/main/docs/TRIVY-RELEASE-EVIDENCE.md. The Action is also accessible on the GitHub Marketplace at https://github.com/marketplace/actions/cra-release-evidence. The author is currently validating the free collector before considering a paid platform, emphasizing that real activation requires producing both Markdown and parseable JSON for an actual product release.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Science

🛻CSS Art: Smoothie Food Truck

This is a submission for Frontend Challenge - Comfort Food Edition, CSS Art . Inspiration 💠I was not sure I was going to enter this challenge at first, because I was not feeling inspired.

More from Sunday 9 August →