Skip to content
Snippets Groups Projects
Unverified Commit 11296cd9 authored by Stefan Prodan's avatar Stefan Prodan
Browse files

Publish Flux Software Bill of Materials (SBOM) in SPDX format

- generate SBOM for Flux Go modules with Syft
- publish the SBOM SPDX JSON files to GitHub releases with GoReleaser

Signed-off-by: default avatarStefan Prodan <stefan.prodan@gmail.com>
parent 677dca0b
No related branches found
No related tags found
No related merge requests found
......@@ -66,6 +66,10 @@ jobs:
- name: Archive the OpenAPI JSON schemas
run: |
tar -czvf ./output/crd-schemas.tar.gz -C schemas .
- name: Setup Syft
uses: fluxcd/pkg//actions/sbom@main
with:
version: "v0.35.1"
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v1
with:
......
......@@ -40,6 +40,8 @@ archives:
format: zip
files:
- none*
sboms:
- artifacts: archive
brews:
- name: flux
tap:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment