Skip to content

feat!: upgrade license scan and cleanup #4479 - #79

Merged
shashi165 merged 2 commits into
mainfrom
feat/upgrade-license-scan
Jun 10, 2026
Merged

shashi165 merged 2 commits into
mainfrom
feat/upgrade-license-scan

Conversation

@shashi165

@shashi165 shashi165 commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ BREAKING — mojaloop/build@2.0.0

Major version bump. The legacy license_scanner command is removed; consumers must move to the new SBOM-based license gate. Pin/upgrade to mojaloop/build@2.0.0 (example/README updated accordingly). Also bumps the executor runtime to Node 24 — validate native-module repos before adopting.


Upgrade license scanning to SBOM-first + harden Grype + cleanup

Replaces the legacy license-scanner tool with an SBOM-first license gate, hardens the Grype job, removes dead code, and bumps the runtime to Node 24.

License scan migration (SBOM-first)

  • New generate_sbom command (Syft → CycloneDX) and license_gate command (@mojaloop/license-scanner-tool, pinned).
  • license_scan (image) and audit_licenses (source) now generate a CycloneDX SBOM and gate it with the published tool; legacy license_scanner command removed.
  • SBOM is stored as an artifact before the gate runs, so it's retained even when the gate fails on a violation.

Grype hardening

  • Fail-closed verdict: added set -euo pipefail and removed the || echo "0" fallbacks in the severity-count step, so a parsing error fails the build instead of silently passing.
  • Pinned scanner versions: new grype_version (v0.114.0) and syft_version (v1.45.0) params; Grype/Syft installs now pin the binary while the vuln DB stays auto-updating.

Cleanup

  • Removed orphaned image_scan job (EOL Anchore Engine, unused by any workflow) and its now-dead anchore/anchore-engine orb import.

Runtime

  • Executor bumped node:22.15.0-alpine3.21 → node:24.15.0-alpine3.23 (Node 24 LTS; alpine3.21 isn't published for Node 24). Per-repo .nvmrc versions remain honored via configure_nvm.

Note

  • Some parts are of the code are generated using Claude Code (Sonnet 4.6)

@elnyry-sam-k elnyry-sam-k left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@shashi165
shashi165 merged commit 2313bf1 into main Jun 10, 2026
9 checks passed
@mojaloopci

Copy link
Copy Markdown

Your development orb(s) have been published. It will expire in 30 days.
You can preview what this will look like on the CircleCI Orb Registry at the following link(s):
https://circleci.com/developer/orbs/orb/mojaloop/build?version=dev:2313bf1e2ead4de2c48bbf363965948521b9db31
https://circleci.com/developer/orbs/orb/mojaloop/build?version=dev:alpha

@mojaloopci

Copy link
Copy Markdown

Your orb has been published to the CircleCI Orb Registry.
You can view your published orb on the CircleCI Orb Registry at the following link:
https://circleci.com/developer/orbs/orb/mojaloop/build?version=2.0.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants