Skip to content

Guardrails / supply-chain

No component the team refuses is in the artifact ​

supply-chain/disallowed-components@v1

No component in the bill of materials is one the team has decided it won't ship, however it got there.

Idsupply-chain/disallowed-components
Versionv1
Categorysupply-chain
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectssbom

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
sbomThe components a build says it ships, read from the bill of materials it already wrote (CycloneDX or SPDX, in JSON, XML or tag-value) and normalized into one list with the licence each component names.none

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "supply-chain/disallowed-components@v1",
              "severity": "error",
              "with": {
                  "components": ""
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
componentsComma separated component names or package URL fragments that are a violation, such as event-stream,pkg:npm/left-pad. If empty, the team hasn't named any and the guardrail skips.``GUARDRAIL_INPUT_COMPONENTS

How to fix ​

Remove the components named in the violations. For a component that arrived transitively, exclude it where it is pulled in and declare the replacement explicitly:

kotlin
implementation("com.company:service") {
    exclude(group = "org.abandoned", module = "parser")
}
implementation("org.maintained:parser:2.1.0")

This guardrail holds the team's list of components it has already decided against: a withdrawn package, one that was taken over, or one an incident was traced to. Without it, that decision lives only in the memory of whoever made it.

More in supply-chain ​

All 6 supply-chain guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412