supply-chain
6 guardrails, all at version v1.
| Guardrail | Default severity | What it checks |
|---|---|---|
supply-chain/components-licensed | warning | Enough of the components in the bill of materials name a licence for the inventory to tell you what the artifact may be distributed under. |
supply-chain/disallowed-components | error | No component in the bill of materials is one the team has decided it won't ship, however it got there. |
supply-chain/disallowed-licenses | error | No component in the bill of materials uses a licence the team has decided it won't ship. |
supply-chain/no-critical-vulnerabilities | error | No dependency of the build has an open finding at or above the severity the team gates on. |
supply-chain/sbom-present | error | An SBOM was produced for this build, so the components that went into the artifact are recorded at build time instead of reconstructed later. |
supply-chain/sbom-standard-format | warning | The bill of materials uses a standard format other tools can read, and declares which version of that format it follows. |
You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.