Skip to content

Guardrails

supply-chain ​

6 guardrails, all at version v1.

GuardrailDefault severityWhat it checks
supply-chain/components-licensedwarningEnough of the components in the bill of materials name a licence for the inventory to tell you what the artifact may be distributed under.
supply-chain/disallowed-componentserrorNo component in the bill of materials is one the team has decided it won't ship, however it got there.
supply-chain/disallowed-licenseserrorNo component in the bill of materials uses a licence the team has decided it won't ship.
supply-chain/no-critical-vulnerabilitieserrorNo dependency of the build has an open finding at or above the severity the team gates on.
supply-chain/sbom-presenterrorAn SBOM was produced for this build, so the components that went into the artifact are recorded at build time instead of reconstructed later.
supply-chain/sbom-standard-formatwarningThe bill of materials uses a standard format other tools can read, and declares which version of that format it follows.

You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.

Buildnote Limited
Registered in England and Wales, Reg: 16140412