The included workflow .github/workflows/svs-scan.yml detects the project type and generates a CycloneDX SBOM in CI, runs SVS, uploads the SARIF report to GitHub code ...