Repository navigation
Add v26.9.0 release posts for sbomify and sbomify-action - #154
Merged
vpetersson merged 2 commits intoSep 25, 2026
Merged
Conversation
Two announcement posts, one per repository, following the existing release-post convention: separate posts published the same day, each cross-linking the other. The platform post leads on SPDX 3 becoming a format sbomify understands rather than one it only stores: 3.0 documents validated against their own schema, scanned through a derived copy instead of skipped, read for the VEX and licence data they carry, and an upload ceiling that a Yocto image SBOM can actually fit through. It also covers the v2 API, the Helm chart, the Trust Center changes and the findings table. The action post leads on the CI platform work — TeamCity, Jenkins, CircleCI and Travis CI reading what their vendors publish rather than falling through to a git checkout — plus the broken GitLab invocation we had published in every non-GitHub example, DOCUMENT_FILE, and SPDX 3 round-trip fidelity. Content drawn from the diffs between v26.8.0 and v26.9.0 in both repositories, filtered to what changes something for a user. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> Co-authored-by: multica-agent <[email protected]>
The post claimed both 3.0.0 and 3.0.1 are now checked against their own schema. The platform vendors no 3.0.0 schema and deliberately does not: schemas.py holds only documents claiming 3.0.1 or later to the vendored official schema, and leaves 3.0/3.0.0 lenient because syft, sbom-tool and JFrog emit 3.0 and 3.0.1 renamed properties after those were written. The "matched none of the bundled schemas, validated as skipped" framing belongs to sbomify-action, which does vendor both schemas and does skip on a miss. On the platform, v26.8.0 ran no schema check on any SPDX 3 document at all — spdx3_validation.py is new in v26.9.0. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> Co-authored-by: multica-agent <[email protected]>
vpetersson
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two announcement posts for the v26.9.0 releases, one per repository, following the existing convention: separate posts published the same day, each cross-linking the other.
content/posts/2026-09-24-announcing-sbomify-v26-9-0-the-one-that-speaks-spdx-3.mdcontent/posts/2026-09-24-announcing-sbomify-action-v26-9-0-the-one-that-runs-on-every-ci.mdWhat they cover, and why that selection
Content is drawn from the diffs between
v26.8.0andv26.9.0in both repositories — 624 commits on the platform, 179 on the action — filtered to changes that alter what a user sees or has to do. Dependency bumps, test infrastructure and internal refactors are left out.Platform post. SPDX 3 is the spine, because four separate dead ends closed at once: a 3.0 document matched none of the bundled schemas and so validated as "skipped" and went through unchecked; osv-scanner and Dependency Track have no SPDX 3 reader, so every such upload came back as a skip telling the uploader to run
syft convertthemselves; the BOM subject was read from whichever package came first rather than fromrootElement; and the upload endpoint advertised 100 MB while Django refused the body at 20 MB, which is exactly where a Yocto image SBOM lands. Around that: the v2 API (artifacts/workspaces, v1 deprecated with no sunset date committed), the Helm chart, Trust Center certification badges, gated components that 404'd instead of showing the request-access gate, CSAF 2.0 discovery, the CISA 2026 Minimum Elements plugin being registered, and the findings-table rebuild behind the component page's 5.1s render and 8.5 MB of HTML.Action post. The CI platform subsystem leads: TeamCity, Jenkins, CircleCI and Travis CI now read what their vendors publish instead of falling through to a git checkout that cannot name a branch on a detached HEAD. Then the GitLab invocation — our own config called
/sbomify.sh, which does not exist, and that had been copied into this site's CI/CD guide and roughly nineteen language guides, so every GitLab, Jenkins and CircleCI example published here was broken. ThenDOCUMENT_FILE, SPDX 3 round-trip fidelity (708 declared-licence relationships in one Yocto document were being rewritten as genericother), and the audit trail no longer recording the build machine's directory layout and username.One editorial call worth a reviewer's attention
The platform post states plainly that a Trust Center release page was publishing severity counts and every finding by ID, package and version to anyone with the link, with no setting behind it, and that there is now an opt-in toggle. That is accurate, and it is the kind of thing customers are better off hearing from us than discovering. It is still a judgement call about wording, so flagging it rather than burying it.
Verification
bun run lint:markdown(dprint) clean.hugo --minify --environment productionbuilds 506 pages, both new permalinks resolving, and every internal link used in the posts resolves to a built page: the v26.8.0 posts,/sbomify-action/, and/sbomify-action/runtimes/.Opened from a fork because this account has no push access to this repository.
🤖 Generated with Claude Code