Skip to content

Add v26.9.0 release posts for sbomify and sbomify-action - #154

Merged
vpetersson merged 2 commits into
sbomify:masterfrom
vpetersson-bot:blog/v26-9-0-release-posts
Sep 25, 2026
Merged

vpetersson merged 2 commits into
sbomify:masterfrom
vpetersson-bot:blog/v26-9-0-release-posts

Conversation

@vpetersson-bot

Copy link
Copy Markdown
Contributor

Two announcement posts for the v26.9.0 releases, one per repository, following the existing convention: separate posts published the same day, each cross-linking the other.

  • content/posts/2026-09-24-announcing-sbomify-v26-9-0-the-one-that-speaks-spdx-3.md
  • content/posts/2026-09-24-announcing-sbomify-action-v26-9-0-the-one-that-runs-on-every-ci.md

What they cover, and why that selection

Content is drawn from the diffs between v26.8.0 and v26.9.0 in both repositories — 624 commits on the platform, 179 on the action — filtered to changes that alter what a user sees or has to do. Dependency bumps, test infrastructure and internal refactors are left out.

Platform post. SPDX 3 is the spine, because four separate dead ends closed at once: a 3.0 document matched none of the bundled schemas and so validated as "skipped" and went through unchecked; osv-scanner and Dependency Track have no SPDX 3 reader, so every such upload came back as a skip telling the uploader to run syft convert themselves; the BOM subject was read from whichever package came first rather than from rootElement; and the upload endpoint advertised 100 MB while Django refused the body at 20 MB, which is exactly where a Yocto image SBOM lands. Around that: the v2 API (artifacts/workspaces, v1 deprecated with no sunset date committed), the Helm chart, Trust Center certification badges, gated components that 404'd instead of showing the request-access gate, CSAF 2.0 discovery, the CISA 2026 Minimum Elements plugin being registered, and the findings-table rebuild behind the component page's 5.1s render and 8.5 MB of HTML.

Action post. The CI platform subsystem leads: TeamCity, Jenkins, CircleCI and Travis CI now read what their vendors publish instead of falling through to a git checkout that cannot name a branch on a detached HEAD. Then the GitLab invocation — our own config called /sbomify.sh, which does not exist, and that had been copied into this site's CI/CD guide and roughly nineteen language guides, so every GitLab, Jenkins and CircleCI example published here was broken. Then DOCUMENT_FILE, SPDX 3 round-trip fidelity (708 declared-licence relationships in one Yocto document were being rewritten as generic other), and the audit trail no longer recording the build machine's directory layout and username.

One editorial call worth a reviewer's attention

The platform post states plainly that a Trust Center release page was publishing severity counts and every finding by ID, package and version to anyone with the link, with no setting behind it, and that there is now an opt-in toggle. That is accurate, and it is the kind of thing customers are better off hearing from us than discovering. It is still a judgement call about wording, so flagging it rather than burying it.

Verification

  • bun run lint:markdown (dprint) clean.
  • hugo --minify --environment production builds 506 pages, both new permalinks resolving, and every internal link used in the posts resolves to a built page: the v26.8.0 posts, /sbomify-action/, and /sbomify-action/runtimes/.

Opened from a fork because this account has no push access to this repository.

🤖 Generated with Claude Code

vpetersson-bot and others added 2 commits September 24, 2026 16:28
Two announcement posts, one per repository, following the existing
release-post convention: separate posts published the same day, each
cross-linking the other.

The platform post leads on SPDX 3 becoming a format sbomify understands
rather than one it only stores: 3.0 documents validated against their own
schema, scanned through a derived copy instead of skipped, read for the
VEX and licence data they carry, and an upload ceiling that a Yocto image
SBOM can actually fit through. It also covers the v2 API, the Helm chart,
the Trust Center changes and the findings table.

The action post leads on the CI platform work — TeamCity, Jenkins,
CircleCI and Travis CI reading what their vendors publish rather than
falling through to a git checkout — plus the broken GitLab invocation we
had published in every non-GitHub example, DOCUMENT_FILE, and SPDX 3
round-trip fidelity.

Content drawn from the diffs between v26.8.0 and v26.9.0 in both
repositories, filtered to what changes something for a user.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Co-authored-by: multica-agent <[email protected]>
The post claimed both 3.0.0 and 3.0.1 are now checked against their own
schema. The platform vendors no 3.0.0 schema and deliberately does not:
schemas.py holds only documents claiming 3.0.1 or later to the vendored
official schema, and leaves 3.0/3.0.0 lenient because syft, sbom-tool and
JFrog emit 3.0 and 3.0.1 renamed properties after those were written.

The "matched none of the bundled schemas, validated as skipped" framing
belongs to sbomify-action, which does vendor both schemas and does skip on
a miss. On the platform, v26.8.0 ran no schema check on any SPDX 3
document at all — spdx3_validation.py is new in v26.9.0.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Co-authored-by: multica-agent <[email protected]>
@vpetersson
vpetersson merged commit 5545d9d into sbomify:master Sep 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants