Switch cve-edge-post.yml to a fixed docker.io/paasup/sbom-pipeline image and paasup-specific Docker Hub credentials, dropping the nvcr.io auth entry.
jq is required to aggregate trivy-reports/*.json into the CVE summary JSON posted to the edge API.