fix(release): wrap goreleaser before-hooks in sh -c (#133) #140
security.yml
on: push
OSV-Scanner (SCA)
7s
Trivy (filesystem + container scan)
8s
Semgrep (SAST)
22s
Gitleaks (secret scan)
11s
jscpd (duplication < 3% on touched code)
14s
SBOM (SPDX + CycloneDX)
21s
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
sbom
|
12.7 KB |
sha256:617509ed1307da4d9bbf5d0f10c2dd8b1de0f01e722beb714004fba9a082d0f1
|
|