-
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Generate SBOM #3468
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Generate SBOM #3468
Conversation
Generate a Software Bill of Materials during the build and attest it.
Codecov ReportAll modified and coverable lines are covered by tests ✅
✅ All tests successful. No failed tests found. Additional details and impacted files@@ Coverage Diff @@
## master #3468 +/- ##
=======================================
Coverage 94.28% 94.28%
=======================================
Files 109 109
Lines 3728 3728
Branches 707 707
=======================================
Hits 3515 3515
Misses 213 213
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Match the artifact name with the file.
Also attest the binaries.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This PR introduces an automated SBOM generation step during the build process and updates the attestation step for artifact verification.
- Added a "Generate SBOM" step using anchore/sbom-action for Windows runners.
- Adjusted the subject-path in the "Attest artifacts" step to include the newly generated SBOM and additional artifact paths.
Generate a Software Bill of Materials during the build and attest it.