minder
minder copied to clipboard
Check for published SBOM after a release
Minder should be able to, at least, check for a published SBOM in the GitHub release assets and/or other well-known locations or by following the breadcrumbs in SECURITY_INSIGHTS.yaml.
This is proposed as SA-11 in https://github.com/ossf/security-baseline/pull/163