From 5e53a2d9f1252668e81bea6a1fd6d7e9d26bcb2f Mon Sep 17 00:00:00 2001 From: Mariano Fuentes Date: Wed, 15 Jul 2026 11:03:15 -0400 Subject: [PATCH 1/2] ci: submit resolved bun tree to GitHub dependency graph (accurate SBOM) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit GitHub does not natively parse bun.lock, so its dependency graph, exported SBOM, and Dependabot only see declared package.json ranges plus the npm package-lock.json in apps/mcp-server — they are blind to the bun dependency tree and to our overrides. Syft parses bun.lock with fully resolved versions, so this workflow scans the repo with Syft (anchore/sbom-action) and submits the result via GitHub's Dependency Submission API. After it runs on main, GitHub's own Export SBOM and Dependabot reflect the real bun tree; the SBOM is also uploaded as a workflow artifact. Runs on main (when lockfiles/manifests change), weekly, and on demand. Needs contents:write for the submission API. No run: steps / no untrusted input, so no workflow-injection surface. Co-Authored-By: Claude Fable 5 --- .github/workflows/sbom.yml | 50 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 .github/workflows/sbom.yml diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml new file mode 100644 index 0000000000..53eca3831f --- /dev/null +++ b/.github/workflows/sbom.yml @@ -0,0 +1,50 @@ +name: SBOM + +# Publishes an accurate SBOM to GitHub's dependency graph. +# +# GitHub does NOT natively parse `bun.lock`, so out of the box its dependency +# graph, exported SBOM, and Dependabot are blind to the bun dependency tree +# (they only see declared package.json ranges + the npm package-lock.json in +# apps/mcp-server). Syft DOES parse bun.lock with fully resolved versions +# (overrides applied), so this workflow scans the repo with Syft and submits +# the resolved tree via GitHub's Dependency Submission API. After this runs on +# `main`, GitHub's own "Export SBOM" and Dependabot reflect the real bun tree. + +on: + push: + branches: [main] + paths: + - 'bun.lock' + - 'apps/mcp-server/package-lock.json' + - '**/package.json' + - '.github/workflows/sbom.yml' + schedule: + - cron: '0 6 * * 1' # weekly, Monday 06:00 UTC — refresh against new advisories + workflow_dispatch: + +permissions: + contents: write # required by the Dependency Submission API + +concurrency: + group: sbom-${{ github.ref }} + cancel-in-progress: true + +jobs: + sbom: + name: Generate & submit SBOM + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v4 + + # Scans the whole repo: Syft reads bun.lock (resolved) and + # apps/mcp-server/package-lock.json. `dependency-snapshot: true` submits + # the result to the dependency graph; the SBOM is also uploaded as a + # workflow artifact for anyone who wants the file directly. + - name: Generate SBOM & submit to dependency graph + uses: anchore/sbom-action@v0 + with: + path: . + format: spdx-json + artifact-name: sbom.spdx.json + dependency-snapshot: true From 5b24cf995592acec4e3200978b4acd2cc0eee5be Mon Sep 17 00:00:00 2001 From: Mariano Fuentes Date: Wed, 15 Jul 2026 11:08:12 -0400 Subject: [PATCH 2/2] ci(security): pin anchore/sbom-action to a commit SHA MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The action runs with contents:write (Dependency Submission API), so the mutable @v0 tag is a supply-chain risk — a retag or repo compromise would run altered third-party code with our write token. Pin to the full commit SHA of v0.24.0 (Syft v1.42.3, which parses bun.lock). Bump SHA + comment together to upgrade. Co-Authored-By: Claude Fable 5 --- .github/workflows/sbom.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml index 53eca3831f..92473ce95b 100644 --- a/.github/workflows/sbom.yml +++ b/.github/workflows/sbom.yml @@ -42,7 +42,10 @@ jobs: # the result to the dependency graph; the SBOM is also uploaded as a # workflow artifact for anyone who wants the file directly. - name: Generate SBOM & submit to dependency graph - uses: anchore/sbom-action@v0 + # Pinned to a full commit SHA (not the mutable @v0 tag): this action + # runs with contents:write, so a retag/compromise must not be able to + # swap in altered code. Bump the SHA + comment together to upgrade. + uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 with: path: . format: spdx-json