Skip to content

Commit 1766f38

Browse files
authored
Merge pull request #117 from SovereignCloudStack/kr/use-json-formatting
🌱 generate SBOM in json format with bom
2 parents 42f5f8e + aca18dc commit 1766f38

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

.github/workflows/release.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -83,12 +83,11 @@ jobs:
8383
- name: Generate SBOM CSO
8484
shell: bash
8585
# To-Do: generate SBOM from source after https://github.com/kubernetes-sigs/bom/issues/202 is fixed
86-
# To-Do: format SBOM output to json after cosign v2.0 is released with https://github.com/sigstore/cosign/pull/2479
8786
run: |
88-
bom generate -o sbom_ci_main_cso_${{ steps.metacso.outputs.version }}-spdx.json \
87+
bom generate --format=json -o sbom_ci_main_cso_${{ steps.metacso.outputs.version }}-spdx.json \
8988
--image=ghcr.io/sovereigncloudstack/cso:${{ steps.metacso.outputs.version }}
9089
91-
- name: Attach SBOM to Container Images cso
90+
- name: Attest SBOM to Container Images cso
9291
run: |
9392
cosign attest --yes --type=spdxjson --predicate sbom_ci_main_cso_${{ steps.metacso.outputs.version }}-spdx.json ghcr.io/sovereigncloudstack/cso@${{ steps.docker_build_release_cso.outputs.digest }}
9493
@@ -132,6 +131,7 @@ jobs:
132131
- manager-image
133132
steps:
134133
- name: Set env
134+
shell: bash
135135
run: echo "RELEASE_TAG=${GITHUB_REF:10}" >> $GITHUB_ENV
136136

137137
- name: checkout code

0 commit comments

Comments
 (0)