Create a GitHub action using scancode.io: - use package/dependencies/vulnaribility data from scancode.io - to output a SPDX/CycloneDX SBOM - upload this as an artifact created by the action (like artifacts created on tag push/release)