File tree Expand file tree Collapse file tree 1 file changed +27
-0
lines changed Expand file tree Collapse file tree 1 file changed +27
-0
lines changed Original file line number Diff line number Diff line change 9
9
tags :
10
10
- ' v*'
11
11
12
+ permissions : {}
13
+
12
14
jobs :
13
15
release :
14
16
runs-on : ubuntu-latest
17
19
contents : write # needed to write releases
18
20
19
21
steps :
22
+ - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
23
+ with :
24
+ persist-credentials : false
25
+
26
+ - uses : actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
27
+ with :
28
+ go-version : stable
29
+ cache : false
30
+ check-latest : true
31
+
32
+ - name : Install bom
33
+ uses : kubernetes-sigs/release-actions/setup-bom@a30d93cf2aa029e1e4c8a6c79f766aebf429fddb # v0.3.1
34
+
35
+ - name : Set tag output
36
+ id : tag
37
+ run : echo "tag_name=${GITHUB_REF#refs/*/}" >> "$GITHUB_OUTPUT"
38
+
39
+ - name : Generate SBOM
40
+ shell : bash
41
+ run : |
42
+ bom generate --format=json -o /tmp/${{github.event.repository.name}}-${{ steps.tag.outputs.tag_name }}.spdx.json .
43
+
20
44
- name : Publish Release
21
45
uses : kubernetes-sigs/release-actions/publish-release@a30d93cf2aa029e1e4c8a6c79f766aebf429fddb # v0.3.1
22
46
env :
23
47
GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
48
+ with :
49
+ assets : " /tmp/${{github.event.repository.name}}-${{ steps.tag.outputs.tag_name }}.spdx.json"
50
+ sbom : false
You can’t perform that action at this time.
0 commit comments