We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent be8801f commit df06b1bCopy full SHA for df06b1b
.github/workflows/release-sbom.yml
@@ -4,6 +4,7 @@ on:
4
types: [published]
5
6
permissions:
7
+ id-token: write
8
contents: write
9
10
jobs:
@@ -19,7 +20,18 @@ jobs:
19
20
path: .
21
format: cyclonedx-json
22
output-file: sbom-cyclonedx.json
23
+ - name: Install cosign
24
+ uses: sigstore/cosign-installer@v3
25
+ - name: Sign SBOM (keyless OIDC)
26
+ run: |
27
+ cosign sign-blob --yes \
28
+ --output-signature sbom-cyclonedx.json.sig \
29
+ --output-certificate sbom-cyclonedx.json.crt \
30
+ sbom-cyclonedx.json
31
- name: Attach SBOM to release
32
uses: softprops/action-gh-releasecbd405e2c4e67a21c47fa9e383d020e4@e28b836
33
with:
- files: sbom-cyclonedx.json
34
+ files: |
35
36
+ sbom-cyclonedx.json.sig
37
+ sbom-cyclonedx.json.crt
0 commit comments