We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent e114787 commit 875712cCopy full SHA for 875712c
1 file changed
.github/workflows/release.yaml
@@ -66,13 +66,16 @@ jobs:
66
- uses: sigstore/cosign-installer@e1523de7571e31dbe865fd2e80c5c7c23ae71eb4 # v3.4.0
67
- uses: advanced-security/sbom-generator-action@375dee8e6144d9fd0ec1f5667b4f6fb4faacefed # v0.0.1
68
id: sbom
69
- working-directory: /tmp
70
env:
71
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ - name: Move sbom to avoid dirty git
72
+ run: mv "$GITHUB_SBOM_PATH" /tmp/sbom/spdx.json
73
+ env:
74
+ GITHUB_SBOM_PATH: ${{ steps.sbom.outputs.fileName }}
75
- uses: goreleaser/goreleaser-action@7ec5c2b0c6cdda6e8bbb49444bc797dd33d74dd8 # v5.0.0
76
with:
77
version: latest
78
args: release --clean
79
80
- GITHUB_SBOM_PATH: ${{ steps.sbom.outputs.fileName }}
81
+ GITHUB_SBOM_PATH: /tmp/sbom.spdx.json
0 commit comments