Review Software Supply Chain
review_software_supply_chainCorrelate CycloneDX/SPDX SBOM quality with CI action pinning, Kubernetes image immutability, artifact signing, and build provenance to assess software-supply-chain risk from supplied artifacts.
Instructions
Correlate CycloneDX/SPDX SBOM quality with CI action pinning, Kubernetes image immutability, artifact signing and build provenance to assess software-supply-chain risk. Use this when an SBOM is available and supply-chain evidence needs to be evaluated together. It analyzes supplied artifacts only and does not call registries, CI systems, or clusters.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| sbomJson | Yes | CycloneDX or SPDX SBOM JSON used as the primary software-supply-chain evidence. | |
| environment | No | Optional target environment used to contextualize supply-chain risk. | |
| workflowYaml | No | Optional GitHub Actions workflow YAML used to inspect action pinning and build controls. | |
| hasProvenance | No | Whether verifiable build provenance or attestation is produced for released artifacts. | |
| artifactSigned | No | Whether released artifacts or images are cryptographically signed. | |
| kubernetesManifestYaml | No | Optional Kubernetes manifest YAML used to inspect runtime image immutability. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| findings | Yes | ||
| riskLevel | Yes | ||
| riskScore | Yes | ||
| policyPack | Yes | ||
| sbomFormat | Yes | ||
| environment | Yes | ||
| findingCount | Yes | ||
| highFindings | Yes | ||
| hasProvenance | Yes | ||
| artifactSigned | Yes | ||
| componentCount | Yes | ||
| mediumFindings | Yes | ||
| recommendedGate | Yes | ||
| sbomSpecVersion | Yes | ||
| correlationPaths | Yes | ||
| criticalFindings | Yes | ||
| metadataCoverage | Yes | ||
| assessmentConfidence | Yes | ||
| mutableRuntimeImages | Yes | ||
| mutableActionReferences | Yes |