Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | /** |
| 2 | * The dependency graph as an SPDX 2.3 JSON document, downloaded as a file: | |
| 3 | * `<owner>-<repo>.spdx.json`. Write and up, as the Security pages. | |
| 4 | */ | |
| 5 | import type { Route } from "./+types/security-sbom"; | |
| 6 | import { requireInsider } from "../../lib/access.server"; | |
| 7 | import { securitySuite } from "../../lib/services.server"; | |
| 8 | import { getViewer, requireUser, unwrap } from "../../lib/session.server"; | |
| 9 | ||
| 10 | export async function loader({ params, context, request }: Route.LoaderArgs) { | |
| 11 | const viewer = getViewer(context) ?? requireUser(context, request); | |
| 12 | await requireInsider(context, params, "push"); | |
| 13 | const document = unwrap(await securitySuite.sbom({ namespace: params.owner, name: params.repo }, viewer)); | |
| 14 | return new Response(`${JSON.stringify(document, null, 2)}\n`, { | |
| 15 | headers: { | |
| 16 | "content-type": "application/spdx+json; charset=utf-8", | |
| 17 | "content-disposition": `attachment; filename="${params.owner}-${params.repo}.spdx.json"`, | |
| 18 | "cache-control": "private, no-store", | |
| 19 | }, | |
| 20 | }); | |
| 21 | } |