“GitHub Action for creating software bill of materials using Syft.”
Local reference
Suspicious dependency
Inferred
Loading file contents…
Loading traits…
Identity
| SHA-256 | c3aedf72d2d4cffb6cad20345cf46abd8be05549e3f9a974050a931c5a10a72c |
|---|---|
| Canonical SHA-256 | 07de37a0b2cce110f1587fe005638b0e068b9280cfcf4312cefa29c244d88e97 |
| Filename | main |
| Package | anchore/sbom-action |
| Version | main |
| PURL | pkg:github/anchore/sbom-action@main |
Origin
| Source | upload |
|---|---|
| Ecosystem | github |
| Domain | github.com |
| URL | https://codeload.github.com/anchore/sbom-action/tar.gz/main |
Timeline
| First seen | 24 Aug 2026 20:57 UTC |
|---|---|
| First analyzed | 24 Aug 2026 21:31 UTC |
| Last analyzed | 24 Aug 2026 21:31 UTC |
| Last updated | 24 Aug 2026 21:31 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | upload |
| Traits version | 72034 |
Not seeing what you expected? Let us know