Skip to content

fix(security): make the SBOM workflow able to describe any release tag - #319

Merged
hyochan merged 5 commits into
mainfrom
fix/sbom-generator-from-default-branch
Aug 13, 2026
Merged

hyochan merged 5 commits into
mainfrom
fix/sbom-generator-from-default-branch

Conversation

@hyochan

@hyochan hyochan commented Aug 12, 2026 •

Copy link
Copy Markdown
Member

Summary

Dispatching sbom.yml for the first time — against the real react-native-iap-16.3.0 release — failed. Two defects, both found by actually running it.

What was wrong

1. The generator was taken from the released commit.

Error: Cannot find module '.../scripts/generate-sbom.mjs'

The workflow checks out the release tag, and that commit predates the generator. This was wrong in both directions: a tag older than the generator could not be described at all, and a generator fix would never reach a regenerated SBOM.

The generator is a tool; the tag is its input. The workflow now restores just the generator scripts from the default branch. Every dependency manifest it reads still comes from the released commit, so the SBOM still describes the release rather than main.

2. The generator's tests ran against the released tree.

not ok 2 - component versions come from the release SSOT
  ENOENT: .../packages/conformance/package.json

react-native-iap-16.3.0 predates packages/conformance, so tests that iterate every releasable component failed on a manifest that was never there. Those tests validate the tree that owns them and already run in ci.yml on every pull request, where the target is correct. Removed from this workflow.

The guard that matters is the step after it, which verifies the produced document: version, tag, and commit must agree, and no local path may appear.

Verified end to end

Dispatched from this branch against the real release. All steps pass, and the artifact is now attached to react-native-iap-16.3.0:

name:       react-native-iap 16.3.0
purl:       pkg:npm/react-native-iap@16.3.0
licence:    MIT
author:     OpenIAP
components: 0          ← correct: this package declares no runtime dependencies
openiap:release:commit = 05add6359c4f99b3f701f7d543beb365142bb57b   ← matches the tag
  • cyclonedx validate --input-version v1_6 → BOM validated successfully
  • gh attestation verify --repo hyodotdev/openiap → exit 0, SLSA v1 predicate, subject digest matches, signed by token.actions.githubusercontent.com, builder .github/workflows/sbom.yml

security/SBOM.md promised retroactive generation that could not work; the update policy now describes what actually happens.

Test plan

  • Workflow dispatched against a real release tag — every step succeeds
  • Published asset passes CycloneDX 1.6 schema validation
  • Provenance attestation verifies against the repository
  • SBOM commit property equals the tag's commit
  • bun audit:docs clean

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Security
    • Improved software bill of materials (SBOM) generation and verification for released versions.
    • Retroactive SBOM updates now use the release’s dependency information while applying current generator improvements.
    • SBOMs now record release and generator revisions for improved traceability.
    • Documentation clarifies that core dependency inventories are reproducible, while license and supplier details may vary with live registry data.

@hyochan hyochan added 🛠 bugfix All kinds of bug fixes 💨 ci Cloud integration labels Aug 12, 2026
@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • .github/pr-previews/pr319-sbom-preview.mp4 is excluded by !**/*.mp4

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 43a4c336-8a9d-4624-9622-7e92f777e6c3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 10136d08-19e8-4c51-a774-76d2b6f3e698

📥 Commits

Reviewing files that changed from the base of the PR and between cb7629b and b5ef88f.

📒 Files selected for processing (10)
  • .claude/commands/audit-security.md
  • .github/workflows/sbom.yml
  • packages/docs/src/pages/docs/security/sbom.tsx
  • scripts/fixtures/historical-releases/google-v1.3.0/openiap-versions.json
  • scripts/fixtures/historical-releases/google-v1.3.0/packages/google/gradle.properties
  • scripts/fixtures/historical-releases/google-v1.3.0/packages/google/openiap/build.gradle.kts
  • scripts/generate-sbom.mjs
  • scripts/generate-sbom.test.mjs
  • security/CRA.md
  • security/SBOM.md

📝 Walkthrough

Walkthrough

The SBOM generator now separates release and generator commits, validates release tags, and records generator metadata. The workflow uses current generator scripts with released dependency manifests. Documentation and tests cover core inventory reproducibility and variable registry metadata.

Changes

SBOM generation policy

Layer / File(s) Summary
Release-aware generator contract
scripts/generate-sbom.mjs, scripts/generate-sbom.test.mjs, scripts/fixtures/historical-releases/*
Generation accepts --tag and --generator-commit, validates release-tag identity, records the generator commit, and tests historical release trees and tag aliases.
Workflow sourcing and verification
.github/workflows/sbom.yml
The workflow overlays default-branch generator scripts onto the release workspace, passes both commit values, verifies the recorded generator commit, and removes upload clobbering.
Core inventory reproducibility policy
security/SBOM.md, security/CRA.md, .claude/commands/audit-security.md, packages/docs/src/pages/docs/security/sbom.tsx
The documentation defines reproducibility from release, generator, and resolver inputs. It treats registry-derived license and supplier data as variable enrichment.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Mergeability Score: ⚪ Minimal · up to b5ef8

This PR updates SBOM generation for historical release tags and aligns the documentation with the workflow's behavior; no actionable merge-blocking risk remains after normal checks and review.

Possibly related PRs

  • hyodotdev/openiap#318: Directly modifies the SBOM workflow, generator, tests, and security documentation.

Suggested labels: 📘 release, 📖 documentation

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: enabling SBOM generation for any release tag.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/sbom-generator-from-default-branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/sbom.yml:
- Around line 58-75: Make SBOM generation inputs explicit: in
.github/workflows/sbom.yml lines 58-75, capture the full generator commit SHA
from FETCH_HEAD and persist it in the generated SBOM or attestation; in
security/SBOM.md lines 318-323, update the byte-identical reproduction claim to
account for the mutable generator revision and live registry metadata, or
document the frozen registry metadata required for exact reproduction.
- Around line 58-75: Add a historical-release compatibility audit for the
mixed-tree workflow where the default-branch scripts are checked out by the
generator step. Create representative historical manifest/tag-alias fixtures or
golden assertions and extend scripts/generate-sbom.test.mjs to verify dependency
completeness and successful SBOM generation for those releases, including cases
that could otherwise skip or fail due to older formats.

In `@security/SBOM.md`:
- Around line 318-323: Remove the --clobber option from the workflow_dispatch
release-asset upload so existing assets cannot be overwritten. Update the SBOM
reproduction policy to state that byte-identical output is not guaranteed when
--with-licenses retrieves live registry metadata, since registry failures can
alter license and supplier fields.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 65bd7b17-0dd8-4487-8f24-970bb1b03d94

📥 Commits

Reviewing files that changed from the base of the PR and between ce9ec53 and cb7629b.

📒 Files selected for processing (2)
  • .github/workflows/sbom.yml
  • security/SBOM.md

Comment thread .github/workflows/sbom.yml
Comment thread security/SBOM.md Outdated
@hyochan

hyochan commented Aug 13, 2026 •

Copy link
Copy Markdown
Member Author

Preview

SBOM documentation now distinguishes the reproducible core inventory from point-in-time registry metadata and records the exact generator commit.

pr319-sbom-preview.mp4

@hyodotdev hyodotdev deleted a comment from coderabbitai Bot Aug 13, 2026
@hyodotdev hyodotdev deleted a comment from coderabbitai Bot Aug 13, 2026
hyochan added a commit that referenced this pull request Aug 13, 2026
## Summary

- Move the 19 tracked PR preview assets to GitHub user attachments in
their original PR bodies or comments.
- Remove `.github/pr-previews` from version control.
- Require temporary local recordings and direct GitHub uploads; blocked
uploads now stop for permission instead of force-adding a Git fallback.

## Verification

- All 20 migrated attachments, including PR #319, return the expected
media type through ranged HTTP requests.
- All 22 affected PR body/comment locations reference their new
`user-attachments` URLs.
- `bun audit:docs`
- `bun audit:parity`
- `bun run audit:release-state`
- Prettier check for the edited source guidance
- `git diff --check`

## Preview

Not applicable: this removes repository-only review media and changes
internal contribution guidance. The attachment and reference checks
above are the relevant proof.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated preview-sharing guidance to require temporary recordings to be
uploaded as attachments and deleted afterward.
  * Prohibited committing one-off preview recordings as fallback assets.
* Added instructions to stop and request maintainer assistance when
attachment uploads are unavailable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Dispatching sbom.yml against react-native-iap-16.3.0 failed with
MODULE_NOT_FOUND: the workflow checks out the release tag, and that
commit predates the generator.

The generator is a tool and the tag is its input, so pinning the tool to
whatever sat in the tagged commit was wrong in both directions — a tag
older than the generator could not be described at all, and a generator
fix would never reach a regenerated SBOM. The workflow now restores just
the generator scripts from the default branch. Every dependency manifest
it reads still comes from the released commit.

security/SBOM.md promised retroactive generation that could not work;
the update policy now describes what actually happens.
The generator's tests validate the tree that owns them, so pointing them
at a released commit fails on any tag from before a component existed —
react-native-iap-16.3.0 predates packages/conformance. They already run
in ci.yml on every pull request, where the target is correct.

The guard that matters is the next step, which verifies the produced
document: version, tag, and commit must agree, and no local path may
appear.
@hyochan
hyochan force-pushed the fix/sbom-generator-from-default-branch branch from eb25971 to 003763d Compare August 13, 2026 02:14
@hyodotdev hyodotdev deleted a comment from coderabbitai Bot Aug 13, 2026
@hyochan
hyochan merged commit ca7af12 into main Aug 13, 2026
12 checks passed
@hyochan
hyochan deleted the fix/sbom-generator-from-default-branch branch August 13, 2026 02:30
hyochan added a commit that referenced this pull request Aug 13, 2026
Complete the remaining issue #323 SBOM verification and guarded recovery work after #318, #319, and #332.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🛠 bugfix All kinds of bug fixes 💨 ci Cloud integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant