-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
enhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededroadmapPlanned feature — not yet startedPlanned feature — not yet started
Description
Summary
Generate CycloneDX or SPDX SBOMs for every release, covering both the Go gateway binary and the Python service dependencies. This strengthens the compliance story and is increasingly required for enterprise adoption.
Acceptance Criteria
- SBOM generated automatically in CI on release tags
- Covers Go modules (gateway, OTel processors) and Python packages (SDK, Episode Store, Policy Engine)
- Published as release artifacts alongside binaries
Milestone
v0.2.0
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededroadmapPlanned feature — not yet startedPlanned feature — not yet started