Skip to content

feat(sbom): remove user fragment#133

Open
reyreavman wants to merge 2 commits into
mainfrom
feat/sbom/remove-user-fragment
Open

feat(sbom): remove user fragment#133
reyreavman wants to merge 2 commits into
mainfrom
feat/sbom/remove-user-fragment

Conversation

@reyreavman

Copy link
Copy Markdown
Collaborator

No description provided.

Remove the sbom.fragment directive that allowed users to manually declare
CycloneDX components in werf.yaml. SBOM is now generated automatically
from controlled inputs: syft scan, base image SBOM, and imported image
SBOMs.

The image-level sbom.gost configuration for per-image GOST security
property overrides is preserved.

Using sbom.fragment in werf.yaml now produces a config error:
"unknown fields: fragment".

E2E test fixtures still reference sbom.fragment and will be migrated
separately.

Signed-off-by: Radmir Khurum <radmir.khurum@flant.com>
Signed-off-by: Radmir Khurum <radmir.khurum@flant.com>
@reyreavman reyreavman force-pushed the feat/sbom/remove-user-fragment branch from c76461e to 673abd3 Compare June 23, 2026 23:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant