Open
Description
We have SBOMs currently for Java and Go contribs. We could use them here as well. I recommend this utility: https://github.com/marketplace/actions/cyclonedx-node-js-generate-sbom (we're using the clyclonedx format elsewhere and it's popular).
Definition of done:
- SBOMs generated and attached to release artifact in GH, or otherwise made publicly available (for every release)
- runtime dependencies only included
- only includes dependencies of module in question (not of repo)
Relates to: open-feature/js-sdk#649