Skip to content

Add Bomly Guard to Security - #877

Open
bomly-guy wants to merge 1 commit into
sdras:mainfrom
bomly-guy:add-bomly-guard
Open

Add Bomly Guard to Security#877
bomly-guy wants to merge 1 commit into
sdras:mainfrom
bomly-guy:add-bomly-guard

Conversation

@bomly-guy

@bomly-guy bomly-guy commented Jul 31, 2026

Copy link
Copy Markdown

Adding bomly-guard, an Apache-2.0 composite action I maintain.

It installs the Bomly CLI and runs bomly diff against the pull request's merge base, then writes the dependency and policy delta to the job summary — optionally also as a PR comment or a SARIF upload. The point is reviewing what a dependency change actually pulls in, at the moment of review.

Appended to the end of Static Analysis → Security, alongside the other dependency and vulnerability actions there. One line, no bold, per contributing.md.

(I first placed this in the loose list at the top of Static Analysis, which was wrong — it does dependency review, not source analysis. Corrected.)

Bomly is a personal open-source project — not affiliated with or endorsed by GitHub.

@bomly-guy bomly-guy changed the title Add Bomly Guard to Static Analysis Add Bomly Guard to Security Jul 31, 2026
@bomly-guy

Copy link
Copy Markdown
Author

Correction — I've moved this from the loose list at the top of Static Analysis into Static Analysis → Security, where it belongs. It reviews dependency changes on a PR rather than analysing source, so it sits better next to Snyk Test Action and the Dependabot/vulnerability entries. Sorry for the noise; the diff is one line either way.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant