
During March 2025, Jan Landa developed SBOM Builder Image Support for the konflux-ci/build-tasks-dockerfiles repository, focusing on enhancing supply-chain transparency in CI/CD workflows. He extended the add_image_reference.py script using Python to inject and relate builder and auxiliary images within SBOMs, introducing a new --builder-image flag for flexible inclusion. Updates to SPDX and CycloneDX formats ensured that full build environments were accurately represented, supporting compliance and traceability. Jan’s work leveraged containerization and scripting skills to address the need for end-to-end visibility in build pipelines, delivering a targeted feature that deepened the project’s approach to software bill of materials management.

Delivered SBOM Builder Image Support for konflux-ci/build-tasks-dockerfiles to inject and relate builder images in SBOMs, including a new --builder-image flag and updates to SPDX and CycloneDX representations to reflect full build environments (including auxiliary images). This work enhances supply-chain transparency, compliance readiness, and debugging visibility across CI tasks. One commit (15298a5ff1ed4d59c6f7ed1e593afbd72ac69880) implements the changes.
Delivered SBOM Builder Image Support for konflux-ci/build-tasks-dockerfiles to inject and relate builder images in SBOMs, including a new --builder-image flag and updates to SPDX and CycloneDX representations to reflect full build environments (including auxiliary images). This work enhances supply-chain transparency, compliance readiness, and debugging visibility across CI tasks. One commit (15298a5ff1ed4d59c6f7ed1e593afbd72ac69880) implements the changes.
Overview of all repositories you've contributed to across your timeline