Skip to content

pin cyclonedx - #2030

Open
mwrock wants to merge 2 commits into
mainfrom
pin
Open

pin cyclonedx#2030
mwrock wants to merge 2 commits into
mainfrom
pin

Conversation

@mwrock

@mwrock mwrock commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

This pins the cyclonedx npm package to a last known version to avoid 403s from harness.

Signed-off-by: Matt Wrock <matt@mattwrock.com>
Copilot AI lite review requested due to automatic review settings August 12, 2026 21:53
@mwrock
mwrock requested a review from a team as a code owner August 12, 2026 21:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins the CycloneDX npm SBOM generator tooling used by the CI workflow so SBOM generation is stable when installing through the internal npm registry proxy.

Changes:

  • Pin @cyclonedx/cyclonedx-npm and @cyclonedx/cyclonedx-library versions via npm exec --package ... to avoid proxy cooldown failures.
  • Adds inline workflow documentation explaining the internal registry cooldown behavior and why pinning is required.
  • Alters the BlackDuck SBOM import step conditional (currently commented out).

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci-main-pull-request-stub.yml Outdated
Signed-off-by: Matt Wrock <matt@mattwrock.com>
Copilot AI review requested due to automatic review settings August 13, 2026 13:34

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants