Skip to content

Pre-release pipeline missing SBOM generation and attestation #1162

@WilliamBerryiii

Description

@WilliamBerryiii

Description

The pre-release pipeline (release-prerelease.yml) does not generate a dependency SBOM or perform SBOM attestation. The stable pipeline has these steps, but the pre-release pipeline was missing them entirely.

Expected Behavior

Pre-release builds should also generate a dependency SBOM using anchore/sbom-action, include file-existence verification guards, and attest both per-VSIX and dependency SBOMs for supply chain integrity.

Impact

Pre-release artifacts lack supply chain attestation, creating an inconsistency with the stable release pipeline and reducing security posture for pre-release consumers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions