Skip to content

Conversation

@github-actions
Copy link

Airflow 3 will need to be updated with package-json.lock but for now
we are fixing the sbom command to work for Airflow 2 (and generate
airflow 2.11 SBOMS.

Changes:

  • passing --github-token parameter which might be helpful to not
    rate-limit GitHub calls

  • allowing to pass either --airflow-site-archive-path or
    --airflow-root-path depending where we want to generate sbom -
    it can be generated in archive folder directly (when we want
    to update historical data) or in the airflow source directory
    when we want to add SBOM to just generated documentation
    during the doc-building phase
    (cherry picked from commit acea31e)

Co-authored-by: Jarek Potiuk jarek@potiuk.com

Airflow 3 will need to be updated with package-json.lock but for now
we are fixing the sbom command to work for Airflow 2 (and generate
airflow 2.11 SBOMS.

Changes:

* passing --github-token parameter which might be helpful to not
  rate-limit GitHub calls

* allowing to pass either `--airflow-site-archive-path` or
  `--airflow-root-path` depending where we want to generate sbom -
  it can be generated in `archive` folder directly (when we want
  to update historical data) or in the airflow source directory
  when we want to add SBOM to **just** generated documentation
  during the doc-building phase
(cherry picked from commit acea31e)

Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
@boring-cyborg boring-cyborg bot added area:dev-tools backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch labels Jun 30, 2025
@potiuk potiuk marked this pull request as ready for review June 30, 2025 22:45
@potiuk potiuk merged commit 4cca258 into v3-0-test Jun 30, 2025
5 checks passed
@potiuk potiuk deleted the backport-acea31e-v3-0-test branch June 30, 2025 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:dev-tools backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant