Skip to content

Merge pull request #230 from Screenly/release-1.0.3 #10

Merge pull request #230 from Screenly/release-1.0.3

Merge pull request #230 from Screenly/release-1.0.3 #10

Workflow file for this run

---
name: Generate SBOMs
on:
push:
tags:
- 'v*'
jobs:
sbom:
permissions:
id-token: write
contents: read
attestations: write
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Upload SBOM
uses: sbomify/github-action@master
env:
TOKEN: ${{ secrets.SBOMIFY_TOKEN }}
COMPONENT_ID: 'UUzAdk8ixV'
LOCK_FILE: 'Cargo.lock'
SBOM_VERSION: ${{ github.ref_name }}
OUTPUT_FILE: 'cli.cdx.json'
OVERRIDE_NAME: true
AUGMENT: true
ENRICH: true
- name: Attest
uses: actions/attest-build-provenance@v1
with:
subject-path: '${{ github.workspace }}/cli.cdx.json'