[`Pitloom`](https://github.com/bact/pitloom) is considered usable now and can generated SBOM with "A" grade on https://kartben.github.io/spdx3_viz/
We may hook Pitloom into Hatchling build process, to generate shacl2code SBOM and put it inside the wheel, following PEP 770 recommendation.
See the real-world generated SBOMs from Pitloom from these PyPI downloads:
- https://pypi.org/project/pitloom/#files
- https://pypi.org/project/licenseid/#files
Download any of the `.whl` file, unzip it, look in `*.dist-info/sboms` subdirectory, there will be a `.spdx3.json` SBOM file. Can try validate it with validator or inspect it with the online visualizer tool above.
#140 is merged and test-sbom.yml is now test SBOM generation for every PR.
See for example,
https://github.com/JPEWdev/shacl2code/actions/runs/32283666106/job/96167992898#step:6:383
See the generated SBOM here https://github.com/JPEWdev/shacl2code/actions/runs/32283666106/artifacts/9376785121